Description
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade.
Published: 2026-07-16
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Snowflake Connector for Python contained an improper hostname verification flaw that allowed a network‑positioned attacker to present a valid certificate for any domain without the connector checking that the hostname matched. An attacker could therefore intercept or redirect HTTPS traffic and capture or alter credentials, query data, and staged file contents. Once the connection was established, the attacker could issue arbitrary SQL within the victim’s connector session, constrained only by the privileges of the Snowflake role. Based on the description, it is inferred that the attacker’s ability to issue arbitrary SQL is limited by the privileges of the affected Snowflake role, thereby constraining the potential damage in an individual account.

Affected Systems

All installations of the Snowflake Connector for Python that were using a version older than 4.7.1 or 3.18.1 are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 9.2 indicates a high severity vulnerability. The EPSS score is under 1 %, showing a currently low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack would require on‑path network access, typically obtained through MITM techniques such as ARP poisoning, DNS spoofing, or BGP hijacking. The required on‑path capability limits the attack to environments where the attacker can position themselves between the connector client and the Snowflake service, but once achieved, the attacker could tamper with traffic and execute SQL commands within the context of the victim's role.

Generated by OpenCVE AI on August 1, 2026 at 08:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Snowflake Connector for Python to version 4.7.1 or the 3.18.1 release, which contains the proper TLS hostname verification fix.
  • Verify that no untrusted network intermediaries are performing TLS interception or proxying for the connector traffic.
  • If an upgrade cannot be applied immediately, enforce strict network path security such as using VPNs with certificate pinning or monitoring for unauthorized certificate changes to reduce the likelihood of an on‑path attacker.

Generated by OpenCVE AI on August 1, 2026 at 08:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Snowflake
Snowflake snowflake-connector-python
Vendors & Products Snowflake
Snowflake snowflake-connector-python

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Important


Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python version 4.7.1. Users must manually upgrade. Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python versions 4.7.1 and 3.18.1. Users must manually upgrade.
References

Thu, 16 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception capability (e.g. ARP/DNS poisoning, rogue access point, BGP hijacking, or malicious proxy/exit node). This vulnerability may have exposed credentials, query data, and staged file contents to interception and tampering, and may have enabled the attacker to issue arbitrary SQL within the context of the victim's connector session. Impact is limited by the privileges of the affected Snowflake role. The fix is available in Snowflake Connector for Python version 4.7.1. Users must manually upgrade.
Title Improper TLS Hostname Verification in Snowflake Connector for Python
Weaknesses CWE-297
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Snowflake Snowflake-connector-python
cve-icon MITRE

Status: PUBLISHED

Assigner: SNOWFLAKE

Published:

Updated: 2026-07-16T12:43:16.112Z

Reserved: 2026-07-16T05:18:59.070Z

Link: CVE-2026-15925

cve-icon Vulnrichment

Updated: 2026-07-16T12:43:09.318Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-16T05:31:35Z

Links: CVE-2026-15925 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-297

    Improper Validation of Certificate with Host Mismatch