PT-2026-85439 · Snowflake · Snowflake Node.Js Driver+3
CVE-2026-85525
·
Published
2026-09-04
·
Updated
2026-09-04
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Snowflake Python driver (affected versions not specified)
Snowflake Go driver (affected versions not specified)
Snowflake JDBC driver (affected versions not specified)
Snowflake Node.js driver (affected versions not specified)
Description
Improper OCSP (Online Certificate Status Protocol) response validation allows a revoked TLS certificate to be accepted as valid. This occurs because OCSP responses are not reliably bound to the certificate being validated, and definitive verification failures are treated as transient. A man-in-the-middle attacker possessing a revoked certificate and its private key for a Snowflake or stage hostname can force the driver to establish a TLS session with an attacker-controlled endpoint. This enables the attacker to read and modify data transmitted within that connection. Successful exploitation requires an on-path position and the corresponding private key.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Go Driver
Snowflake Jdbc Driver
Snowflake Node.Js Driver
Snowflake Python Driver