CVE-2026-104002
5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.
To remediate this issue, users should upgrade to version 3.35.0.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | powertools-lambda-python | 3.6.0 <= 3.34.0 | affected |
Weaknesses
- CWE-390: CWE-390 Detection of error condition without action
References
- https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0
- https://aws.amazon.com/security/security-bulletins/2026-123-aws/
- https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.