2026-123-AWSHigh

CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

Published
October 1, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-123-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 14:00 PM PDT Description: Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to mask. Impacted versions: >=3.6.0 AND Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)