Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Snowflake

First CVE: Mar 2, 2010Active for: 16 yearsTotal CVEs: 38
23.5
VTI Score
Low

Snowflake operates a cloud data platform and an ecosystem of connectors and client libraries that integrate with a wide range of languages and frameworks, presenting a supply-chain dependency footprint despite a narrow product roster. The vendor's vulnerability exposures cluster around its connector and SDK products—including JDBC connectors, Streamlit integrations, and C/C++ client libraries—and recur through weakness classes spanning command injection, default permission misconfigurations, sensitive information leakage into logs, race conditions, and path-traversal flaws that reflect both integration complexity and deployment-configuration sensitivity. These weakness classes are characteristic of widely embedded client software and suggest that remediation often extends to the applications and platforms that consume the connector libraries rather than being isolated to Snowflake alone. Defenders should treat connector and SDK advisories from this vendor as supply-chain signals and audit dependent applications for misconfiguration and privilege escalation through default or inherited settings. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
38
Total CVEs
More Total CVEs than 98% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Snowflake over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2010
16 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-13749HIGH
Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling
Jun 29, 20268.839NONO
CVE-2026-13751CRITICAL
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives co
Jun 29, 20269.638NONO
CVE-2026-13744HIGH
Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project co
Jun 29, 20268.838NONO
CVE-2026-13752HIGH
Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulner
Jun 29, 20268.035NONO
CVE-2026-13748MEDIUM
Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attac
Jun 29, 20266.331NONO
CVE-2026-13750MEDIUM
Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker co
Jun 29, 20265.528NONO
CVE-2023-30535HIGH
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to
Apr 14, 20238.828NONO
CVE-2026-13746MEDIUM
Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted value
Jun 29, 20265.426NONO
CVE-2023-34230HIGH
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential
Jun 8, 20238.825NONO
CVE-2023-34231HIGH
gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL aut
Jun 8, 20238.825NONO
View all 38 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products38 CVEs
42%
47%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (50.0%)
Network17 (44.7%)
Unknown2 (5.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (73.7%)
High8 (21.1%)
Unknown2 (5.3%)
User Interaction
None23 (60.5%)
Unknown2 (5.3%)
Required13 (34.2%)
Privileges Required
Low21 (55.3%)
High1 (2.6%)
None14 (36.8%)
Unknown2 (5.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Snowflake.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Snowflake — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Snowflake's Products

View all 4 CNAs →

Top CWEs