CVE-2026-3293 | snowflakedb snowflake-jdbc up to 4.0.1 JDBC URL SdkProxyRoutePlanner.java SdkProxyRoutePlanner nonProxyHosts redos (Issue 2505)
A vulnerability categorized as problematic has been discovered in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the argument nonProxyHosts can lead to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2026-3293. The attack can only be executed locally. Furthermore, there is an exploit available.
A patch should be applied to remediate this issue.