Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)
Medium5.3CVE-2026-104002 · Published Oct 1, 2026
Bulletin ID: 2026-123-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/01/2026 14:00 PM PDT Description: Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to mask. Impacted versions: >=3.6.0 AND <=3.34.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Oct 2 | Severity: Unrated to Medium |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- NVD
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Uncontrolled recursion in the Ion reader in Amazon Ion Python | High7.5 | No fix yet |
| Oct 1 | Argument injection in AWS security-agent-mcp-server diff scan | High8.2 | No fix yet |
| Oct 1 | Mount Option Injection in Amazon EFS CSI Driver | Medium6.5 | No fix yet |
| Sep 29 | GluonTS arbitrary command execution during model deserialization | High7.8 | No fix yet |
| Sep 25 | REMOVE_BASE_PATH strips every leading repetition of the base path, not just one | Low | 1.1.0 |
| Sep 24 | Type confusion in AWS pgcollection allows remote code execution | High8.8 | No fix yet |