CVE-2025-46330

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in version 2.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowflake:connector_for_c\/c\+\+:*:*:*:*:*:*:*:*

History

09 May 2025, 19:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.3
CWE NVD-CWE-noinfo
First Time Snowflake
Snowflake connector For C\/c\+\+
CPE cpe:2.3:a:snowflake:connector_for_c\/c\+\+:*:*:*:*:*:*:*:*
References () https://github.com/snowflakedb/libsnowflakeclient/security/advisories/GHSA-ch37-53v3-m4cm - () https://github.com/snowflakedb/libsnowflakeclient/security/advisories/GHSA-ch37-53v3-m4cm - Vendor Advisory
References () https://github.com/snowflakedb/libsnowflakeclient/pull/882/commits/8120a057e041722e114ed2c5dbed3b5a649f72e2 - () https://github.com/snowflakedb/libsnowflakeclient/pull/882/commits/8120a057e041722e114ed2c5dbed3b5a649f72e2 - Patch

29 Apr 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 05:15

Updated : 2025-05-09 19:37


NVD link : CVE-2025-46330

Mitre link : CVE-2025-46330


JSON object : View

Products Affected

snowflake

  • connector_for_c\/c\+\+
CWE
NVD-CWE-noinfo CWE-573

Improper Following of Specification by Caller