AWS Lambda Powertools(Python)中的数据处理实用程序存在一个“失败时开放”(fail-open)的错误处理问题,可能导致攻击者读取到应用程序原本打算进行掩码处理的敏感字段值。 为缓解此问题,用户应升级至 3.35.0 版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | powertools-lambda-python | 3.6.0≤ 3.34.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | powertools-lambda-python | 3.6.0 ~ 3.34.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97662 | 8.2 HIGH | Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbi |
| CVE-2026-103505 | 6.5 MEDIUM | AWS EFS CSI Driver Mount Option Injection via mounttargetipmap |
No comments yet