Executive brief
Snowflake's JDBC Driver is a library that applications use to connect to Snowflake databases. Versions 4.2.0 through 4.3.3 fail to properly validate the account identifier when using auto-configuration (connections.toml), allowing an attacker with control over the account parameter to redirect login credentials to a malicious server. An attacker could capture reusable login credentials and replay them to gain unauthorized access to the database with the victim application's privileges.
Technical details
The vulnerability is an improper input validation flaw in the auto-configuration path of Snowflake JDBC Driver. When an application uses jdbc:snowflake:auto with a connections.toml configuration that omits an explicit host, the driver synthesizes the target URL from the account parameter without adequate validation. An attacker able to control the account value can inject URL components (dots, slashes, etc.) to redirect the HTTPS connection to an arbitrary endpoint. The attack requires the application to use jdbc:snowflake:auto with connections.toml lacking an explicit host and a lower-trust principal able to influence the account parameter; ordinary JDBC URLs are unaffected. Successful exploitation allows the attacker to capture and replay credential-bearing login requests. The fix, released in Snowflake JDBC Driver 4.3.4, adds strict validation: account labels may contain only letters, digits, underscores, and hyphens; port must be numeric (1–65535); protocol must be http or https; and the ACCOUNT property rejects values containing path separators, query characters, anchors, or whitespace.
Affected products
- Snowflake JDBC Driver 4.2.0 through 4.3.3
Timeline
- 2026-09-04: disclosed
- 2026-09-03: patched: Fix released in version 4.3.4