Vulnerability in Snowflake JDBC Driver Affecting Local Argument Manipulation
CVE-2026-3293
Key Information:
- Vendor
Snowflakedb
- Status
- Vendor
- CVE Published:
- 27 February 2026
Badges
What is CVE-2026-3293?
A vulnerability has been found in the Snowflake JDBC driver, specifically within the SdkProxyRoutePlanner function. This weakness allows for local exploitation through manipulation of the nonProxyHosts argument, resulting in inefficient regular expression complexity. An attacker could leverage this flaw to execute local attacks that may disrupt normal operations. A public exploit has been made available, highlighting the need for immediate remediation. Users are encouraged to apply the patch identified as commit 5fb0a8a318a2ed87f4022a1f56e742424ba94052 to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
snowflake-jdbc 4.0.0
snowflake-jdbc 4.0.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
