Skip to content
AWSAWS-2026-058

Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK

UnratedCVE-2026-15737 · Published Jul 16, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-058-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/16/2026 10:00 AM PDT Description: Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. We identified CVE-2026-15737 in the OpenTelemetry instrumentation of the SDK. Affected versions wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, where a local authenticated user with CloudWatch Logs read access could access the potentially sensitive content. Impacted versions:  1.4.8, 1.5.0 Resolution: This issue has been addressed in Bedrock AgentCore Python SDK version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups. Workarounds: No workarounds are available. Upgrade Bedrock AgentCore Python SDK to ve...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-058-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/16/2026 10:00 AM PDT Description: Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. We identified CVE-2026-15737 in the OpenTelemetry instrumentation of the SDK. Affected versions wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, where a local authenticated user with CloudWatch Logs read access could access the potentially sensitive content. Impacted versions:  1.4.8, 1.5.0 Resolution: This issue has been addressed in Bedrock AgentCore Python SDK version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups. Workarounds: No workarounds are available. Upgrade Bedrock AgentCore Python SDK to version 1.5.1 or later. References: CVE-2026-15737 GHSA-hqf8-7w95-9r33 Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-058-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK Bulletin ID: 2026-058-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/16/2026 10:00 AM PDT Description: Bedrock AgentCore Python SDK (bedrock-agentcore) is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. We identified CVE-2026-15737 in the OpenTelemetry instrumentation of the SDK. Affected versions wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, where a local authenticated user with CloudWatch Logs read access could access the potentially sensitive content. Impacted versions:  1.4.8, 1.5.0 Resolution: This issue has been addressed in Bedrock AgentCore Python SDK version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups. Workarounds: No workarounds are available. Upgrade Bedrock AgentCore Python SDK to version 1.5.1 or later. References: CVE-2026-15737 GHSA-hqf8-7w95-9r33 Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected v

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Path traversal and arbitrary file write in the workflow linters of...
UnratedJul 17
Issue with Athena Federated Query Synapse Connector
UnratedJul 17
OS command injection in jsii-diff in AWS jsii
UnratedJul 15
Credential disclosure in Strands Agents Tools elasticsearch_memory tool
UnratedJul 15
aws-load-balancer-controller: insufficient isolation
Medium5.8Jul 14
AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
UnratedJul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.