PT-2026-64236 · Snowflake · Snowflake Jdbc Driver+2
CVE-2026-16870
·
Published
2026-07-24
·
Updated
2026-07-24
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libsnowflakeclient versions prior to 2.9.2
Snowflake PHP PDO Driver versions prior to 4.1.0
Snowflake ODBC Driver versions prior to 3.19.0
Description
Multiple issues exist that could lead to remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path allows remote code execution if an attacker uploads a file with a crafted encryption metadata field to a shared internal stage. Additionally, an out-of-bounds write in the same download path enables memory corruption via a crafted initialization vector metadata field on a shared stage. Furthermore, improper validation of connection parameters allows attacker-controlled input to redirect outbound authentication requests, including credentials and tokens, to an external endpoint. This specific impact occurs in embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are active.
Recommendations
Update libsnowflakeclient to version 2.9.2.
Update Snowflake PHP PDO Driver to version 4.1.0.
Update Snowflake ODBC Driver to version 3.19.0.
Exploit
Fix
RCE
Memory Corruption
SSRF
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Jdbc Driver
Snowflake Php Pdo Driver
Libsnowflakeclient