CVE detail
CVE-2026-3293
A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 5fb0a8a318a2ed87f4022a1f56e742424ba94052. A patch should be applied to remediate this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 4.5
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/?submit.760428vuldb.com
No excerpt available.
Exploitvuldb.comFeb 27, 2026, 6:18 AM - https://vuldb.com/?id.348035vuldb.com
No excerpt available.
Exploitvuldb.comFeb 27, 2026, 6:18 AM - https://vuldb.com/?ctiid.348035vuldb.com
No excerpt available.
Exploitvuldb.comFeb 27, 2026, 6:18 AM - https://snowflakecomputing.atlassian.net/browse/SNOW-3104251snowflakecomputing.atlassian.net
No excerpt available.
Vendor Advisorysnowflakecomputing.atlassian.netFeb 27, 2026, 6:18 AM No excerpt available.
Exploitgithub.comFeb 27, 2026, 6:18 AMNo excerpt available.
Exploitgithub.comFeb 27, 2026, 6:18 AM- https://github.com/snowflakedb/snowflake-jdbc/commit/5fb0a8a318a2ed87f4022a1f56e742424ba94052github.com
No excerpt available.
Exploitgithub.comFeb 27, 2026, 6:18 AM No excerpt available.
Exploitgithub.comFeb 27, 2026, 6:18 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.90 · max 0 stars
- snowflakedb/snowflake-jdbcHigh confidencegithubNVD Exploit reference0 starsDiscovered Jul 11, 2026, 9:20 PM
NVD labels the source link as Exploit; this is not independent verification of the repository's code.
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73556CVSS 5.3 · Medium
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.…
- CVE-2026-72912CVSS 4.3 · Medium
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CP…
- CVE-2026-70489CVSS 6.5 · Medium
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automation…
- CVE-2026-49485CVSS 7.5 · High
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept a…
- CVE-2026-49477CVSS 7.5 · High
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to ca…
- CVE-2026-48125CVSS 5.3 · Medium
UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service…