VYPR

PyPI package

snowflake-connector-python

pkg:pypi/snowflake-connector-python

Vulnerabilities (7)

  • CVE-2026-15925CriJul 16, 2026
    affected < 3.18.1fixed 3.18.1

    Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access cou

  • CVE-2025-24795MedJan 29, 2025
    affected >= 2.3.7, < 3.13.1fixed 3.13.1

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when tempora

  • CVE-2025-24794MedJan 29, 2025
    affected >= 2.7.12, < 3.13.1fixed 3.13.1

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses p

  • CVE-2025-24793HigJan 29, 2025
    affected >= 2.2.5, < 3.13.1fixed 3.13.1

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.

  • CVE-2024-49750MedOct 24, 2024
    affected < 3.12.3fixed 3.12.3

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcod

  • CVE-2023-34233HigJun 8, 2023
    affected < 3.0.2fixed 3.0.2

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order

  • CVE-2022-42965LowNov 9, 2022
    affected < 2.8.2fixed 2.8.2

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method