Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86597— Sensitive information written to logs by Snowflake drivers

Quick assessment

Affected
Snowflake Snowflake Connector for Python
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 Snowflake 的 Python、Go、JDBC、Node.js、PHP PDO 和 ODBC 驱动程序中,敏感信息被插入到日志文件中。 在现有日志脱敏机制未能覆盖所有受影响的日志路径和数据类型的情况下,该漏洞允许认证令牌、查询结果加密密钥、预签名云存储 URL 以及 SAML 断言等敏感信息被写入诊断日志中。 如果攻击者拥有对日志目标位置(如本地文件系统、日志聚合服务或 CI/CD 制品存储库)的读取权限,他们可能获取到有效的凭证和解密密钥。若这些凭证在访问时仍有效,攻击

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sensitive information written to logs by Snowflake drivers
Source: CVE Program / CVE List V5
Vulnerability Description
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in the patched versions listed above. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Snowflake Snowflake Connector for Python 0 ~ 4.7.3 -
Snowflake Snowflake Go Driver 0 ~ 2.2.0 -
Snowflake Snowflake JDBC Driver 0 ~ 4.3.4 -
Snowflake Snowflake Node.js Driver 0 ~ 3.3.0 -
Snowflake Snowflake PHP PDO Driver 3.4.0 ~ 4.2.0 -
Snowflake Snowflake ODBC Driver 3.16.0 ~ 3.20.0 -

II. Public POCs for CVE-2026-86597

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86597

登录查看更多情报信息。

Vendor Pages for CVE-2026-86597 (5)

Other References for CVE-2026-86597 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86597

No comments yet


Leave a comment