Vulnerabilities > CVE-2025-46330 - Improper Following of Specification by Caller vulnerability in Snowflake Connector for C/C++

047910
CVSS 3.3 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
local
low complexity
snowflake
CWE-573

Summary

libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in version 2.2.0.

Vulnerable Configurations

Part Description Count
Application
Snowflake
51