CVE-2025-46330

LOW

Snowflake Connector for C/C++ 0.5.0-2.1.9 - Denial of Service via Malformed Request Retry Handling

Title source: llm
STIX 2.1

Description

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in version 2.2.0.

Scores

CVSS v3 3.3
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-573
Status published
Products (1)
snowflake/connector_for_c\/c\+\+ 0.5.0 - 2.2.0
Published Apr 29, 2025
Tracked Since Feb 18, 2026