net.snowflake:snowflake-jdbc
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting net.snowflake:snowflake-jdbcpage 1 of 1
- CVE-2023-30535HIGHCVSS 7.3EG 7.3fixed in 3.13.292023-04-14
vulnerable: 2.8.0 ... 3.9.2 (146 versions)
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up…
- CVE-2024-43382MEDIUMCVSS 5.9EG 5.9fixed in 3.20.02024-10-30
vulnerable: 3.10.0 ... 3.9.2 (135 versions)
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption.
- CVE-2025-24789HIGHCVSS 7.8EG 7.8fixed in 3.22.02025-01-29
vulnerable: 3.10.0 ... 3.9.2 (142 versions)
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authen…
- CVE-2025-24790MEDIUMCVSS 4.4EG 4.4fixed in 3.22.02025-01-29
vulnerable: 3.10.0 ... 3.9.2 (115 versions)
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporar…
- CVE-2025-27496LOWCVSS 3.3EG 3.3fixed in 3.23.12025-03-13
vulnerable: 3.0.13 ... 3.9.2 (159 versions)
Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG…
- CVE-2026-3293MEDIUMCVSS 5.5EG 5.52026-02-27
vulnerable: 2.8.0 ... 4.0.1 (189 versions)
A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handle…
- CVE-2026-86597MEDIUMCVSS 6.5EG 6.5fixed in 4.3.42026-09-08
vulnerable: 2.8.0 ... 4.3.3 (196 versions)
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be w…
Check whether net.snowflake:snowflake-jdbc is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for net.snowflake:snowflake-jdbc CVEs against the assets you own.
Book a Demo →