Skip to main content
Components
Vulnerabilities
Security Events
Pricing
MCP
API
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
net.snowflake/snowflake-jdbc 4.3.3 | Vulne… | Sonatype Guide
Get full component data and automated fixes with Sonatype Guide.
Sign up for free
maven
net.snowflake
snowflake-jdbc
4.3.3
snowflake-jdbc 4.3.3
Latest
net.snowflake
Published
Aug 18, 2026
•
Policy
compliance
maven Registry
Developer Trust Score
Recommended Version:
x.y.z
Recommended upgrade that meets your policy.
Compare Versions
Overview
Overview
Versions
196
Versions
196
Vulnerabilities
4
Vulnerabilities
4
Dependencies
0
Dependencies
0
Reset filters
Severity
Critical
(0)
High
(0)
Medium
(2)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
6.9
CVE-2026-54518
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.
affected
Severity
Medium
Published
Jun 16, 2026
6.5
sonatype-2020-0026
netty-handler - Improper Certificate Validation [ formerly CVE-2023-4586 ]
affected
Severity
Medium
Published
Feb 4, 2020