Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85525

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade.

A flaw was found in Snowflake drivers, including Python, Go, JDBC, and Node.js. This flaw involves improper Online Certificate Status Protocol (OCSP) response validation, which allows a revoked Transport Layer Security (TLS) certificate to be accepted as valid. A man-in-the-middle attacker, possessing a revoked certificate and its private key for a Snowflake hostname, could exploit this to establish a TLS session with the driver. This would enable the attacker to read and modify data transmitted within the intercepted connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-feature-server-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2528435snowflake-connector-python: github.com/snowflakedb/snowflake-go: snowflake-sdk: net.snowflake/snowflake-jdbc: Snowflake Drivers: Data interception via improper OCSP response validation

EPSS

Процентиль: 1%
0.00105
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
12 дней назад

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), and Snowflake Node.js Driver v3.3.0. Users must manually upgrade.

CVSS3: 7.4
github
12 дней назад

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage hostname could cause the driver to establish a TLS session to the attacker-controlled endpoint anyway, allowing the attacker to read and modify data transmitted within that connection. Successful exploitation requires that on-path position and the corresponding private key, and impact is limited to data carried within the intercepted connection. The fix is available in the patched versions listed above. Users must manually upgrade.

EPSS

Процентиль: 1%
0.00105
Низкий

7.4 High

CVSS3