CVE-2026-3293Disclosure(snowflake / snowflake_jdbc)

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 5fb0a8a318a2ed87f4022a1f56e742424ba94052. A patch should be applied to remediate this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-1333

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • snowflake_jdbc

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
snowflake_jdbc

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-27: 3Technical Details · 2026-02-27: 302-27
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets5 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3293 Inefficient Regular Expression Complexity in Snowflake JDBC URL Ha... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3293 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely references CVE-2026-3293, noting an inefficient regex vulnerability in Snowflake JDBC URLs, and provides a link to a vulnerability details page, without further technical or exploit information.

    0000030
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3293 A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/i… https://www.cve.org/CVERecord?id=CVE-2026-3293

    Post summary

    A new vulnerability in Snowflake JDBC’s SdkProxyRoutePlanner has been disclosed, affecting versions up to 4.0.1, but no exploit, patch, or active use has been reported.

    00000100
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3293 - snowflakedb snowflake-jdbc JDBC URL http://SdkProxyRoutePlanner.java SdkProxyRoutePlanner redos Intel Report: https://ift.tt/0lnGbSt

    Post summary

    The post serves as a threat alert announcing CVE-2026-3293, highlighting potential redos via SdkProxyRoutePlanner, but it does not provide proof-of-concept, exploit code, or active exploitation evidence.

    000002
    341 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnowflakesnowflake_jdbc---

Explore more