-
Notifications
You must be signed in to change notification settings - Fork 516
Open
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSourcestatus-pr_pending_mergeA PR is made and is under reviewA PR is made and is under reviewstatus-triage_doneInitial triage done, will be further handled by the driver teamInitial triage done, will be further handled by the driver team
Description
The currently vendored version of urllib3 (1.26.18) is affected by the security vulnerability CVE-2025-50181, see details in the following sources:
Therefore, scanners like Nexus IQ from Sonatype report snowflake-connector-python as affected as well. The Sonatype severity is reported as "High risk CVSS score" (CVSS4: 7.1). In the enterprise context, this leads to build failures of pipelines, depending on the settings.
Could you please have a look if there is an upgrade path or the possibility of patching the vendored version to fix it?
wyardley, jguilindro and natebransc
Metadata
Metadata
Assignees
Labels
security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSourcestatus-pr_pending_mergeA PR is made and is under reviewA PR is made and is under reviewstatus-triage_doneInitial triage done, will be further handled by the driver teamInitial triage done, will be further handled by the driver team