PT-2025-18134 · Unknown · Libsnowflakeclient
Published
2025-04-29
·
Updated
2025-05-09
·
CVE-2025-46330
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
libsnowflakeclient versions 0.5.0 through 2.2.0
Description
The issue concerns the Snowflake Connector for C/C++, which incorrectly treats malformed requests that cause the HTTP response status code 400 as able to be retried. This could hang the application until SF CON MAX RETRY requests were sent. The problem has been patched in version 2.2.0.
Recommendations
For versions 0.5.0 through 2.2.0, update to version 2.2.0 to resolve the issue. As a temporary workaround, consider restricting the number of retries for malformed requests to prevent the application from hanging.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libsnowflakeclient