CVE-2026-15925
Snowflake Snowflake Connector for Python
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access could exploit this by intercepting or redirecting network traffic and presenting a certificate signed by any trusted CA for any domain, causing the connector to accept connections without validating that the certificate matched the requested hostname. Successful exploitation requires an on-path traffic interception cap...
- CVSS
- 9.2
- EPSS
- 0.18% 7.45% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.16