Showing 1 vulnerability on this page for Snowflake SQLAlchemy

Signals CISA KEV Ransomware Nuclei
Snowflake vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemy

Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic upsert endpoint, potentially enabling read access to data visible to the application's database role or modification of values within the same MERGE statement. Improper literal ren

CWE-73CWE-89Jul 14, 2026
CVSS8.3v3.1EPSS0.267%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX