Multiple Security Vulnerabilities in Snowflake Libsnowflakeclient
CVE-2026-16870
What is CVE-2026-16870?
Multiple security vulnerabilities in Snowflake's libsnowflakeclient prior to version 2.9.2 could allow for remote code execution and credential exfiltration. A stack-based buffer overflow found in the file download path may enable attackers to execute arbitrary code on a victim host by uploading specially crafted files containing manipulated encryption metadata. This exploit is particularly impactful when shared internal stages are used by principals with varying privilege levels. Additionally, an out-of-bounds write vulnerability can result in memory corruption due to attacker-controlled write operations. Attackers can exploit this by utilizing a crafted initialization vector metadata field on the same shared stage. Furthermore, improper validation of connection parameters allows attackers to redirect authentication requests, including sensitive credentials, to their controlled endpoints, particularly in embedding deployments where lesser-privileged principals can manipulate connection settings. Users are advised to upgrade to libsnowflakeclient version 2.9.2 to mitigate these risks.
Affected Version(s)
Snowflake libsnowflakeclient 0.1.1 < 2.9.2
