CVE-2026-104002

Summary

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. 

To remediate this issue, users should upgrade to version 3.35.0.

Affected Software

VendorProductVersion RangeStatus
AWSpowertools-lambda-python3.6.0 <= 3.34.0affected

Weaknesses

  • CWE-390: CWE-390 Detection of error condition without action

References