snowflake-connector-python
Snowflake Connector for Python
Activity
- Latest release
- 4d ago
- Total releases
- 184
- Cadence
- ~13 days
- Last 12 months
- 23
Reach
- Stars
- 729
Details
- License
- Apache-2.0
- First release
- Aug 31, 2017
| Version | Released | |
|---|---|---|
5.0.0rc3
pre
| ||
5.0.0rc2
pre
| ||
4.7.3
patch
| ||
5.0.0rc1
pre
| ||
4.7.2
patch
| ||
5.0.0b6
pre
| ||
5.0.0b5
pre
| ||
3.18.1
patch
| ||
4.7.1
patch
| ||
4.7.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0b4
pre
| ||
5.0.0b3
pre
| ||
4.6.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0b2
pre
| ||
4.5.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
5.0.0b1
pre
| ||
4.4.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.3.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.2.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.1
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.1.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.0.0
major
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.18.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.17.4
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.17.3
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.17.2
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.17.1
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.17.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.16.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.15.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.14.1
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.14.0
minor
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.13.2
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.13.1
patch
1 CVE
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.13.0
minor
4 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev | ||
3.12.4
patch
4 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev | ||
3.12.3
patch
4 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev | ||
3.12.2
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.12.1
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.12.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.11.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.10.1
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.10.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.9.1
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.9.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.8.1
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.8.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.7.1
patch
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.7.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.6.0
minor
5 CVEs
CVE-2026-15925
PYSEC-2026-3920
GHSA-5cc2-282f-jjq2
Sep 10, 2026
Snowflake Connector for Python improperly verifies TLS hostnames
Critical
Network
Low
None
None
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 159 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.13.1
3.13.2
3.14.0
3.14.1
3.15.0
3.16.0
3.17.0
3.17.1
3.17.2
3.17.3
3.17.4
3.18.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
4.0.0
4.1.0
4.1.1
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.7.0
Fixed in
3.18.1
4.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2025-24795
PYSEC-2025-28
GHSA-r2x6-cjg7-8r43
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the Snowflake Connector for Python will cache temporary credentials locally in a world-readable file. This vulnerability affects versions 2.3.7 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.3.10
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
+ 55 more Show less
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24793
PYSEC-2025-26
GHSA-2vpq-fh52-j3wv
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.2.10
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
+ 68 more Show less
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2025-24794
PYSEC-2025-27
GHSA-m4f6-vcj4-w5mx
Jan 29, 2025
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1. Affected versions
2.7.12
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
+ 27 more Show less
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.12.3
3.12.4
3.13.0
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.13.1
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2024-49750
GHSA-5vvg-pvhp-hv2m
PYSEC-2024-191
Oct 24, 2024
The Snowflake Connector for Python stores sensitive data in logs
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IssueSnowflake recently learned about and remediated a set of vulnerabilities in the Snowflake Connector for Python. Under specific conditions, certain users credentials (or portions of those credentials) were logged locally by the Connector to the users own systems. The credentials were not logged by Snowflake. These vulnerabilities affect versions up to and including 3.12.2. Snowflake fixed the issue in version 3.12.3. Vulnerability DetailsWhen the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the “passcode” parameter) and Azure SAS tokens. Additionally, the SecretDetector logging formatter, if enabled, contained bugs which caused it to not fully redact JWT tokens and certain private key formats. SolutionSnowflake released version 3.12.3 of the Snowflake Connector for Python, which fixes these issues. We recommend users upgrade to version 3.12.3 and review their logs for any potentially sensitive information that may have been captured. Additional InformationIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
1.4.10
1.4.11
1.4.12
1.4.13
1.4.14
1.4.15
1.4.16
1.4.17
1.4.5
1.4.6
1.4.7
1.4.8
+ 135 more Show less
1.4.9
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.6.0
1.6.1
1.6.10
1.6.11
1.6.12
1.6.2
1.6.3
1.6.4
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.10
1.7.11
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.2.1
2.2.10
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.6.2
2.7.0
2.7.1
2.7.10
2.7.11
2.7.12
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.0a1
3.1.0a2
3.1.1
3.10.0
3.10.1
3.11.0
3.12.0
3.12.1
3.12.2
3.2.0
3.2.1
3.3.0
3.3.0b1
3.3.1
3.4.0
3.4.1
3.5.0
3.6.0
3.7.0
3.7.1
3.8.0
3.8.1
3.9.0
3.9.1
Fixed in
3.12.3
References
Updated Sep 10, 2026 · Source: OSV.dev |