Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85525— Improper OCSP response validation in Snowflake drivers

Quick assessment

Affected
Snowflake Snowflake Connector for Python
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snowflake 的 Python、Go、JDBC 和 Node.js 驱动程序中存在 OCSP 响应验证不当 的漏洞。由于 OCSP 响应未可靠地与正在验证的证书进行绑定,且将确定性的验证失败视为临时性错误,导致已吊销的 TLS 证书可能被误判为有效。 持有已吊销证书及其私钥(对应 Snowflake 主机名或 stage 主机名)的中间人攻击者,可迫使驱动程序仍然与其控制的端点建立 TLS 会话,从而能够读取并修改该连接中传输的数据。成功利用此漏洞需要攻击者处于通信路径上的位置,并掌握相应的私钥;其影响范围仅

CVSS 7.4 · High EPSS 0.10% · P1

Affected Version Matrix 4

VendorProduct Version RangeStatus
Snowflake Snowflake Connector for Python < 4.7.3 affected
Snowflake Snowflake Go Driver < 2.2.0 affected
Snowflake Snowflake JDBC Driver < 4.3.4 affected
Snowflake Snowflake Node.js Driver < 3.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85525

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper OCSP response validation in Snowflake drivers
Source: CVE Program / CVE List V5
Vulnerability Description
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Snowflake Snowflake Connector for Python 0 ~ 4.7.3 -
Snowflake Snowflake Go Driver 0 ~ 2.2.0 -
Snowflake Snowflake JDBC Driver 0 ~ 4.3.4 -
Snowflake Snowflake Node.js Driver 0 ~ 3.3.0 -

II. Public POCs for CVE-2026-85525

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85525

登录查看更多情报信息。

Vendor Pages for CVE-2026-85525 (3)

Other References for CVE-2026-85525 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85525

No comments yet


Leave a comment