PT-2025-18134 · Unknown · Libsnowflakeclient

Published

2025-04-29

·

Updated

2025-05-09

·

CVE-2025-46330

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions libsnowflakeclient versions 0.5.0 through 2.2.0
Description The issue concerns the Snowflake Connector for C/C++, which incorrectly treats malformed requests that cause the HTTP response status code 400 as able to be retried. This could hang the application until SF CON MAX RETRY requests were sent. The problem has been patched in version 2.2.0.
Recommendations For versions 0.5.0 through 2.2.0, update to version 2.2.0 to resolve the issue. As a temporary workaround, consider restricting the number of retries for malformed requests to prevent the application from hanging.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2025-46330
GHSA-CH37-53V3-M4CM

Affected Products

Libsnowflakeclient