Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
UnratedCVE-2026-92943 · Published Sep 17, 2026
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-middle positioned on the network could present a certificate issued for an unrelated hostname by any certificate authority in the device trust store, impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic. Both SDK default connection paths were affected: X.509 mutual authentication on port 8883 and WebSocket with SigV4 on port 443. The port 443 ALPN path was not affected. Impacted versions: >=1.5.3 AND <=1.6.0 (on Python 3.7 and later) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib | Unrated | No fix yet |
| Sep 22 | Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492... | Unrated | No fix yet |
| Sep 22 | Potential denial of service when configured to send Retry packets in s2n-quic | Unrated | No fix yet |
| Sep 22 | Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService | Unrated | No fix yet |
| Sep 16 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS | Unrated | No fix yet |
| Sep 14 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM... | Unrated | No fix yet |