CVE-2026-85525 describes a critical flaw in Snowflake's Python, Go, JDBC, and Node.js drivers where improper OCSP response validation allowed revoked TLS certificates to be accepted as valid. The vulnerability stemmed from OCSP responses not being reliably bound to the certificate under validation, and definitive verification failures being treated as transient errors. A man-in-the-middle attacker possessing a revoked certificate and its private key for a Snowflake or stage hostname could intercept TLS sessions. This would allow the attacker to read and modify data transmitted within the intercepted connection. Successful exploitation requires an on-path network position and the corresponding private key for a revoked certificate. Impact is scoped to data carried within the intercepted TLS connection. Patches are available across affected driver versions and users must manually upgrade to remediate the issue.