Snowflake Vulnerabilities and Affected Products
Vulnerabilities associated with Snowflake Python APIs.
Products
Clear product- Snowflake CLI7 vulnerabilities
- Cortex Code CLI1 vulnerability
- Snowflake Connector for Python1 vulnerability
- Snowflake libsnowflakeclient1 vulnerability
- Snowflake ODBC1 vulnerability
- Snowflake ODBC Driver1 vulnerability
- Snowflake PHP PDO Driver1 vulnerability
- Snowflake Python APIs1 vulnerability
- Snowflake Spark Connector1 vulnerability
- Snowflake SQLAlchemy1 vulnerability
- snowflake_jdbc1 vulnerability
- Snowpark Python SDK1 vulnerability
- Terraform Provider for Snowflake1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-19594HIGH | Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege EscalationInsufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=` characters in query string values. An attacker with access to a downstream application built on snowflake.core could exploit the path traversal by supplying `..` as an object name, causing … | CVSS8.1v3.1 | EPSS0.395% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |