目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-85525— Snowflake 驱动程序 错误 OCSP 响应验证漏洞

一分钟漏洞结论

影响对象
Snowflake Snowflake Connector for Python
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Snowflake 的 Python、Go、JDBC 和 Node.js 驱动程序中存在 OCSP 响应验证不当 的漏洞。由于 OCSP 响应未可靠地与正在验证的证书进行绑定,且将确定性的验证失败视为临时性错误,导致已吊销的 TLS 证书可能被误判为有效。 持有已吊销证书及其私钥(对应 Snowflake 主机名或 stage 主机名)的中间人攻击者,可迫使驱动程序仍然与其控制的端点建立 TLS 会话,从而能够读取并修改该连接中传输的数据。成功利用此漏洞需要攻击者处于通信路径上的位置,并掌握相应的私钥;其影响范围仅

CVSS 7.4 · High EPSS 0.10% · P1

影响版本矩阵 4

厂商产品 版本范围状态
Snowflake Snowflake Connector for Python < 4.7.3 affected
Snowflake Snowflake Go Driver < 2.2.0 affected
Snowflake Snowflake JDBC Driver < 4.3.4 affected
Snowflake Snowflake Node.js Driver < 3.3.0 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-85525 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Improper OCSP response validation in Snowflake drivers
来源: CVE Program / CVE List V5
Vulnerability Description
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Snowflake Snowflake Connector for Python 0 ~ 4.7.3 -
Snowflake Snowflake Go Driver 0 ~ 2.2.0 -
Snowflake Snowflake JDBC Driver 0 ~ 4.3.4 -
Snowflake Snowflake Node.js Driver 0 ~ 3.3.0 -

二、漏洞 CVE-2026-85525 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-85525 的情报信息

登录查看更多情报信息。

CVE-2026-85525 厂商页面 (3)

CVE-2026-85525 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85525

暂无评论


发表评论