CVE-2026-33682Patch(snowflake / streamlit)

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch snowflake streamlit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the `ComponentRequestHandler`, filesystem paths are resolved using `os.path.realpath()` or `Path.resolve()` before sufficient validation occurs. On Windows systems, supplying a malicious UNC path (e.g., `\\attacker-controlled-host\share`) can cause the Streamlit server to initiate outbound SMB connections over port 445. When Windows attempts to authenticate to the remote SMB server, NTLMv2 challenge-response credentials of the Windows user running the Streamlit process may be transmitted. This behavior may allow an attacker to perform NTLM relay attacks against other internal services and/or identify internally reachable SMB hosts via timing analysis. The vulnerability has been fixed in Streamlit Open Source version 1.54.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • streamlit

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
streamlit

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-27: 2Patch / Workaround · 2026-03-27: 2Technical Details · 2026-03-27: 203-27
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Patch

    Streamlit on Windows has an unauthenticated SSRF vulnerability (CVE-2026-33682) that can expose NTLM credentials, risking unauthorized access. This flaw bypasses usual security checks. Patch immediately to prevent credential theft. #CyberSecurity #InfoSec https://t.co/bdIM8ngxDj

    Post summary

    Streamlit on Windows has an unauthenticated SSRF vulnerability (CVE-2026-33682) that can expose NTLM credentials; the advisory urges users to patch immediately to prevent credential theft.

    0000056
    53 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33682 Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthentic… https://www.cve.org/CVERecord?id=CVE-2026-33682

    Post summary

    The CVE-2026-33682 vulnerability is an unauthenticated authentication bypass in Streamlit Open Source prior to v1.54.0, with the fix available in version 1.54.0; no PoC, exploit code, or active exploitation is reported.

    00000127
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsnowflakestreamlit-windows-

Explore more