CVE-2025-46330
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in version 2.2.0.
Scoring
- Severity
- LOW
- CVSS base score
- 3.3
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.16%
- CWE
- CWE-573
- Published
- 2025-04-29
- Last modified
- 2026-03-13
Affected products
- snowflakedb libsnowflakeclient
Weakness type
Related vulnerabilities
- CVE-2026-59998 — sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior:...
- CVE-2026-41583 — ZEBRA: Consensus Divergence in Transparent Sighash Hash-Type Handling
- CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
- CVE-2025-69287 — BSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2025-69202 — axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
- CVE-2019-14829 — A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier...