Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the target stage during the execution of GET/PUT commands. This key by itself does not grant access to any sensitive data without additional access authorizations, and is not logged server-side by Snowflake. Snowflake fixed the issue in version 3.23.1.
{
"cwe_ids": [
"CWE-532"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/27xxx/CVE-2025-27496.json",
"cna_assigner": "GitHub_M"
}"2026-07-22T04:01:39Z"
[
{
"signature_type": "Line",
"target": {
"file": "src/test/java/net/snowflake/client/util/SecretDetectorTest.java"
},
"deprecated": false,
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ef81582ce2f1dbc3c8794a696c94f4fe65fad507",
"id": "CVE-2025-27496-3bea7516",
"signature_version": "v1",
"digest": {
"line_hashes": [
"158023756002892986376210159853145184043",
"272690835264833104451498613639574631613"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/main/java/net/snowflake/client/jdbc/SnowflakeFileTransferAgent.java",
"function": "parseCommandInGS"
},
"deprecated": false,
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ef81582ce2f1dbc3c8794a696c94f4fe65fad507",
"id": "CVE-2025-27496-5c2e61f6",
"signature_version": "v1",
"digest": {
"function_hash": "237975492394291871509921333486950650316",
"length": 470.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/main/java/net/snowflake/client/util/SecretDetector.java"
},
"deprecated": false,
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ef81582ce2f1dbc3c8794a696c94f4fe65fad507",
"id": "CVE-2025-27496-6002296c",
"signature_version": "v1",
"digest": {
"line_hashes": [
"14850864510599380832621476614014088531",
"176886968517307085086192309817993428126",
"282361796916280988540234336655560539084",
"122954836223329039247883955304364862777",
"1481910811414032351256690958105506369",
"323636132194624915994907427121223917161",
"118230845301602428611742272574461677692",
"176991439462914864374062027367818665901",
"234336993407596980450944883320320563320",
"165740908587491805001087916523090134487"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "src/main/java/net/snowflake/client/util/SecretDetector.java",
"function": "maskSecrets"
},
"deprecated": false,
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ef81582ce2f1dbc3c8794a696c94f4fe65fad507",
"id": "CVE-2025-27496-7477532c",
"signature_version": "v1",
"digest": {
"function_hash": "202097965115584435742278324065516612252",
"length": 127.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/main/java/net/snowflake/client/jdbc/SnowflakeFileTransferAgent.java"
},
"deprecated": false,
"source": "https://github.com/snowflakedb/snowflake-jdbc/commit/ef81582ce2f1dbc3c8794a696c94f4fe65fad507",
"id": "CVE-2025-27496-b90ac40e",
"signature_version": "v1",
"digest": {
"line_hashes": [
"55091043553161822764003362932965854696",
"90099098380919243543607092848555463003",
"282728738826450803212419938852542786956",
"189402425676898320006395606676801370287",
"53826491034780492123043742101433917548",
"337337387755609992759506962000791249578",
"326618887255551099025263563259090202679",
"12331002050842794351220640814564978872"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-27496.json"