CVE-2024-56528: Snowplow Stream Collector
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.
Affected products
- Snowplow Stream Collector: from 3.0.0, before 3.3.0 (fixed in 3.3.0)
Published 2025-04-03. Last modified 2026-06-17.