CVE-2026-15925 involves improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1. This issue may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. To exploit this, an attacker would need on-path network access to intercept or redirect traffic and present a certificate signed by any trusted CA [truncated]
CVE-2026-15183 is a critical vulnerability in Snowflake Spark Connector versions prior to 3.2.1. Multiple input validation vulnerabilities can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. This vulnerability affects users of Snowflake Spark Connector versions prior to 3.2.1 and [truncated]