PT-2026-85439 · Snowflake · Snowflake Node.Js Driver+3

CVE-2026-85525

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Snowflake Python driver (affected versions not specified) Snowflake Go driver (affected versions not specified) Snowflake JDBC driver (affected versions not specified) Snowflake Node.js driver (affected versions not specified)
Description Improper OCSP (Online Certificate Status Protocol) response validation allows a revoked TLS certificate to be accepted as valid. This occurs because OCSP responses are not reliably bound to the certificate being validated, and definitive verification failures are treated as transient. A man-in-the-middle attacker possessing a revoked certificate and its private key for a Snowflake or stage hostname can force the driver to establish a TLS session with an attacker-controlled endpoint. This enables the attacker to read and modify data transmitted within that connection. Successful exploitation requires an on-path position and the corresponding private key.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85525

Affected Products

Snowflake Go Driver
Snowflake Jdbc Driver
Snowflake Node.Js Driver
Snowflake Python Driver