Snowflake operates a cloud data platform and an ecosystem of connectors and client libraries that integrate with a wide range of languages and frameworks, presenting a supply-chain dependency footprint despite a narrow product roster. The vendor's vulnerability exposures cluster around its connector and SDK products—including JDBC connectors, Streamlit integrations, and C/C++ client libraries—and recur through weakness classes spanning command injection, default permission misconfigurations, sensitive information leakage into logs, race conditions, and path-traversal flaws that reflect both integration complexity and deployment-configuration sensitivity. These weakness classes are characteristic of widely embedded client software and suggest that remediation often extends to the applications and platforms that consume the connector libraries rather than being isolated to Snowflake alone. Defenders should treat connector and SDK advisories from this vendor as supply-chain signals and audit dependent applications for misconfiguration and privilege escalation through default or inherited settings. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Snowflake over time
Signals from CVEs in this vendor scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13749HIGH Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling | Jun 29, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-13751CRITICAL Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives co | Jun 29, 2026 | 9.6 | 38 | NO | NO |
CVE-2026-13744HIGH Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project co | Jun 29, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-13752HIGH Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulner | Jun 29, 2026 | 8.0 | 35 | NO | NO |
CVE-2026-13748MEDIUM Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attac | Jun 29, 2026 | 6.3 | 31 | NO | NO |
CVE-2026-13750MEDIUM Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker co | Jun 29, 2026 | 5.5 | 28 | NO | NO |
CVE-2023-30535HIGH Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to | Apr 14, 2023 | 8.8 | 28 | NO | NO |
CVE-2026-13746MEDIUM Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted value | Jun 29, 2026 | 5.4 | 26 | NO | NO |
CVE-2023-34230HIGH snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential | Jun 8, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-34231HIGH gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL aut | Jun 8, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (38 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Snowflake.
Media articles that mention a CVE ID that affects a product developed by Snowflake — matched by CVE ID, not by vendor name.