Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Snowflake — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting Snowflake. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page provides a comprehensive aggregation of security vulnerabilities associated with the Snowflake data cloud platform, focusing on known weakness types and associated tags. It collects detailed records of discovered flaws, including configuration errors, authentication bypasses, and privilege escalation issues, covering incidents reported from 2018 through the present. By centralizing this data, the resource enables security professionals and administrators to effectively track Snowflake’s official security advisories and public disclosures as they emerge. Users can utilize this tool to understand the broader context of specific weakness classes affecting the platform, allowing for better risk assessment and mitigation planning. Additionally, the page serves as a historical reference for looking up a product’s vulnerability trajectory, helping teams identify patterns in recurring issues or deprecated security controls within the Snowflake ecosystem. This structured approach ensures that stakeholders have immediate access to critical information without needing to search multiple disparate sources. The content is designed to support proactive defense strategies by highlighting both past and current threats relevant to Snowflake deployments. Readers can filter and analyze the data to prioritize remediation efforts based on severity and relevance to their specific organizational environment.

CVE IDTitleCVSSSeverityPublished
CVE-2026-15925 Improper TLS Hostname Verification in Snowflake Connector for Python — Snowflake Connector for PythonCWE-297--2026-07-16
CVE-2026-15736 Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy — Snowflake SQLAlchemyCWE-89 8.3 High2026-07-14
CVE-2026-15183 Input Validation Vulnerabilities in Snowflake Spark Connector — Snowflake Spark ConnectorCWE-89--2026-07-14
CVE-2026-15067 Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could Allow Privilege Escalation and Unauthorized Snowflake Account Takeover — Terraform Provider for SnowflakeCWE-89 8.8 High2026-07-08
CVE-2026-15062 SQL Injection in Snowflake Snowpark Python SDK — Snowpark Python SDKCWE-89 9.6 Critical2026-07-08
CVE-2026-13752 Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands — Snowflake CLICWE-89 6.0 Medium2026-06-29
CVE-2026-13751 Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load — Snowflake CLICWE-918 4.1 Medium2026-06-29
CVE-2026-13750 Snowflake CLI Sensitive Credential Exposure Through Debug Logging — Snowflake CLICWE-532 5.5 Medium2026-06-29
CVE-2026-13749 Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection — Snowflake CLICWE-94 8.8 High2026-06-29
CVE-2026-13748 Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction — Snowflake CLICWE-22 6.3 Medium2026-06-29
CVE-2026-13746 Snowflake CLI SQL Injection Through Improper Neutralization of Local CLI Parameters — Snowflake CLICWE-89 3.6 Low2026-06-29
CVE-2026-13744 Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input — Snowflake CLICWE-89 8.3 High2026-06-29
CVE-2026-6442 Improper Command Detection Logic Allows RCE in Cortex Code Command-Line Interface — Cortex Code CLICWE-1286 8.3 High2026-04-16
CVE-2025-46614 Snowflake ODBC Driver 安全漏洞 — Snowflake ODBCCWE-532 3.3 Low2025-04-28

This page lists every published CVE security advisory associated with Snowflake. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.