Summit 26 from June 1-4 in San Francisco

Lead your organization in the era of agents and enterprise intelligence.

CVE ID

  • CVE-2025-46330 - Malformed requests returning HTTP 400 are incorrectly retried, potentially hanging the application.

CWE ID

  • CWE-573 (Improper Following of Specification by Caller)

CPEs

  • cpe:2.3:a:snowflake:connector_for_c/c++:*:*:*:*:*:*:*:* (versions >= 0.5.0, < 2.2.0)

Affected versions

  • 0.5.0 to before 2.2.0

Patched versions:

  • 2.2.0

Description

  • libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status code 400, as able to be retried. This could hang the application until SF_CON_MAX_RETRY requests were sent. This issue has been patched in version 2.2.0.

Resolution

  • Upgrade to libsnowflakeclient version 2.2.0 or later.

Where Data Does More

  • 30-day free trial
  • No credit card required
  • Cancel anytime