CVE-2026-92903Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 09/17/2026 Severity High CVE-2026-86600Workload identity attestation generated before login host validation in Snowflake drivers Exploitation status Not known exploited Fix YesAffected product S Snowflake Connector for Python Published 09/08/2026 Severity High CVE-2026-86597Sensitive information written to logs by Snowflake drivers Exploitation status Not known exploited Fix YesAffected product S Snowflake Connector for Python Published 09/08/2026 Severity Medium CVE-2026-85528Snowflake JDBC Driver auto-configuration account validation permits credential redirection Exploitation status Not known exploited Fix YesAffected product S Snowflake JDBC Driver Published 09/04/2026 Severity Medium CVE-2026-85525Improper OCSP response validation in Snowflake drivers Exploitation status Not known exploited Fix YesAffected product S Snowflake Connector for Python Published 09/04/2026 Severity High CVE-2026-19594Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation Exploitation status Not known exploited Fix YesAffected product S Snowflake Python APIs Published 08/12/2026 Severity High CVE-2026-16870Multiple Security Vulnerabilities in Snowflake libsnowflakeclient Exploitation status Not known exploited Fix YesAffected product S Snowflake Libsnowflakeclient Published 07/24/2026 Severity High CVE-2026-15925Improper TLS Hostname Verification in Snowflake Connector for Python Exploitation status Not known exploited Fix YesAffected product S Snowflake Connector for Python Published 07/16/2026 Severity Critical CVE-2026-15736Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy Exploitation status Not known exploited Fix YesAffected product S Snowflake SQLAlchemy Published 07/14/2026 Severity High CVE-2026-15183Input Validation Vulnerabilities in Snowflake Spark Connector Exploitation status Not known exploited Fix YesAffected product S Snowflake Spark Connector Published 07/14/2026 Severity Critical CVE-2026-15067Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could Allow Privilege Escalation and Unauthorized Snowflake Account Takeover Exploitation status Not known exploited Fix YesAffected product T Terraform Provider for Snowflake Published 07/08/2026 Severity High CVE-2026-15062SQL Injection in Snowflake Snowpark Python SDK Exploitation status Not known exploited Fix YesAffected product S Snowpark Python SDK Published 07/08/2026 Severity Critical CVE-2026-13752Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity Medium CVE-2026-13751Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity Medium CVE-2026-13750Snowflake CLI Sensitive Credential Exposure Through Debug Logging Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity Medium CVE-2026-13749Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity High CVE-2026-13748Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity Medium CVE-2026-13746Snowflake CLI SQL Injection Through Improper Neutralization of Local CLI Parameters Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity Low CVE-2026-13744Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input Exploitation status Not known exploited Fix YesAffected product S Snowflake CLI Published 06/29/2026 Severity High CVE-2026-10804Streamlit Palette hashing.py weak hash Exploitation status Public exploit Fix YesAffected product S Streamlit Published 06/04/2026 Severity Low CVE-2026-6442Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface Exploitation status Not known exploited Fix Not confirmed Affected product C Cortex Code CLI Published 04/16/2026 Severity High CVE-2026-33682Streamlit on Windows has Unauthenticated SSRF Vulnerability (NTLM Credential Exposure) Exploitation status Not known exploited Fix YesAffected product S streamlit Published 03/26/2026 Severity Medium CVE-2026-3293snowflakedb snowflake-jdbc JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner redos Exploitation status Public exploit Fix YesAffected product S snowflake-jdbc Published 02/27/2026 Severity Medium CVE-2025-46329Snowflake Connector for C/C++ inserts client-side encryption key in DEBUG logs Exploitation status Not known exploited Fix YesAffected product L libsnowflakeclient Published 04/29/2025 Severity Low CVE-2025-46330Snowflake Connector for C/C++ retries malformed requests Exploitation status Not known exploited Fix YesAffected product L libsnowflakeclient Published 04/29/2025 Severity Low CVE-2025-46328NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file Exploitation status Not known exploited Fix YesAffected product S snowflake-connector-nodejs Published 04/28/2025 Severity Low CVE-2025-46327Go Snowflake Driver has race condition when checking access to Easy Logging configuration file Exploitation status Not known exploited Fix YesAffected product G gosnowflake Published 04/28/2025 Severity Low CVE-2025-46326Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file Exploitation status Not known exploited Fix YesAffected product S snowflake-connector-net Published 04/28/2025 Severity Low CVE-2025-46614Exploitation status Not known exploited Fix YesAffected product S Snowflake ODBC Published 04/28/2025 Severity Low CVE-2025-27496Snowflake JDBC Driver client-side encryption key in DEBUG logs Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-jdbc Published 03/13/2025 Severity Low CVE-2025-24795The Snowflake Connector for Python uses insecure cache files permissions Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-python Published 01/29/2025 Severity Medium CVE-2025-24794The Snowflake Connector for Python uses insecure deserialization of the OCSP response cache Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-python Published 01/29/2025 Severity Medium CVE-2025-24793Snowflake Connector for Python has an SQL Injection in write_pandas Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-python Published 01/29/2025 Severity High CVE-2025-24788Snowflake Connector for .NET has weak temporary files permissions Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-net Published 01/29/2025 Severity Medium CVE-2025-24790Snowflake JDBC uses insecure temporary credential cache file permissions Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-jdbc Published 01/29/2025 Severity Medium CVE-2025-24789Snowflake JDBC allows an untrusted search path on Windows Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-jdbc Published 01/29/2025 Severity High CVE-2025-24791snowflake-connector-nodejs has incorrect validation of temporary credential cache file permissions Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-nodejs Published 01/29/2025 Severity Medium CVE-2024-43382Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 10/30/2024 Severity Medium CVE-2024-49750Snowflake Connector for Python has sensitive data in logs Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-python Published 10/24/2024 Severity Medium CVE-2024-42474Streamlit Path Traversal Security Vulnerability on Windows Exploitation status Not known exploited Fix Not confirmed Affected product S streamlit Published 08/12/2024 Severity Medium CVE-2024-28851Elevation of privilege in Snowflake Hive MetaStore Connector Helper script Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-hive-metastore-connector Published 03/15/2024 Severity Medium CVE-2023-51662Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL) Exploitation status Not confirmed Fix Not confirmed Affected product S snowflake-connector-net Published 12/22/2023 Severity Medium CVE-2023-34230Snowflake Connector vulnerable to Command Injection Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-net Published 06/08/2023 Severity High CVE-2023-34233Snowflake Python Connector vulnerable to Command Injection Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-python Published 06/08/2023 Severity High CVE-2023-34232Snowflake NodeJS Driver vulnerable to Command Injection Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-connector-nodejs Published 06/08/2023 Severity High CVE-2023-34231Snowflake Golang Driver vulnerable to Command Injection Exploitation status Not known exploited Fix YesAffected product G gosnowflake Published 06/08/2023 Severity High CVE-2023-30535Snowflake JDBC vulnerable to command injection via SSO URL authentication Exploitation status Not known exploited Fix Not confirmed Affected product S snowflake-jdbc Published 04/14/2023 Severity High CVE-2023-27494Streamlit Cross-site Scripting vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product S streamlit Published 03/16/2023 Severity Medium CVE-2022-42965Exponential ReDoS in snowflake-connector-python leads to denial of service Exploitation status Public exploit Fix YesAffected product S snowflake-connector-python Published 11/09/2022 Severity Low CVE-2022-35918Streamlit directory traversal vulnerability Exploitation status Not known exploited Fix YesAffected product S streamlit Published 08/01/2022 Severity Medium CVE-2010-0797Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 03/02/2010 Severity Unknown CVE-2010-0798Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 03/02/2010 Severity Unknown