VYPR
Vendor

Snowflake

Products
19
CVEs
48
Across products
71
Status
Private

Products

19

Recent CVEs

48
View all 48 CVEs →
  • CVE-2026-6442HigApr 16, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository,…

  • CVE-2026-19594HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution…

  • CVE-2023-34233HigJun 8, 2023
    risk 0.50cvss 8.8epss 0.02

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order…

  • CVE-2023-34231HigJun 8, 2023
    risk 0.50cvss 8.8epss 0.02

    gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be…

  • CVE-2023-34230HigJun 8, 2023
    risk 0.48cvss 7.3epss 0.01

    snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious…

  • CVE-2023-30535HigApr 14, 2023
    risk 0.48cvss 7.3epss 0.02

    Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up a malicious, publicly accessible server…

  • CVE-2025-24789HigJan 29, 2025
    risk 0.44cvss 7.8epss 0.00

    Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an…

  • CVE-2026-15925CriJul 16, 2026
    risk 0.41cvss epss 0.00

    Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access…

  • CVE-2023-34232HigJun 8, 2023
    risk 0.41cvss 7.3epss 0.02

    snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1)…

  • CVE-2025-24793HigJan 29, 2025
    risk 0.39cvss 7.0epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the…

  • CVE-2024-43382MedOct 30, 2024
    risk 0.38cvss 5.9epss 0.00

    Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.

  • CVE-2025-24794MedJan 29, 2025
    risk 0.37cvss 6.7epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses…

  • CVE-2024-42474MedAug 12, 2024
    risk 0.35cvss 6.5epss 0.01

    Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when…

  • CVE-2022-35918MedAug 1, 2022
    risk 0.35cvss 6.5epss 0.02

    Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files,…

  • CVE-2023-51662MedDec 22, 2023
    risk 0.32cvss 6.0epss 0.00

    The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List…

  • CVE-2023-27494MedMar 16, 2023
    risk 0.31cvss 5.9epss 0.00

    Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with…

  • CVE-2024-49750MedOct 24, 2024
    risk 0.29cvss 5.5epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo…

  • CVE-2025-24788MedJan 29, 2025
    risk 0.26cvss 5.0epss 0.00

    snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to…

  • CVE-2026-33682MedMar 26, 2026
    risk 0.24cvss 4.7epss 0.00

    Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of…

  • CVE-2025-24795MedJan 29, 2025
    risk 0.22cvss 4.4epss 0.00

    The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when…