Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15737— Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK

Quick assessment

Affected
AWS bedrock-agentcore
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

AWS Bedrock AgentCore SDK是AWS公司开源的一个用于将本地 AI 智能体零基础设施部署到 AWS 的 SDK,支持多种开源框架,提供运行时、记忆、网关、代码解释器等企业级服务。 Amazon Bedrock AgentCore SDK 1.4.8版本和1.5.0版本存在日志信息泄露漏洞,该漏洞源于OpenTelemetry instrumentation未过滤或屏蔽原始用户提示和代理响应,可能导致本地认证用户访问CloudWatch日志中的敏感数据。

CVSS 5.7 · Medium EPSS 0.38% · P30

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 2

VendorProduct Version RangeStatus
AWS bedrock-agentcore 1.4.8 affected
1.5.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15737

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
Source: CVE Program / CVE List V5
Vulnerability Description
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, exposing sensitive content to any principal with log read access. We recommend you upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过日志文件的信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Amazon Bedrock AgentCore SDK 日志信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
AWS Bedrock AgentCore SDK是AWS公司开源的一个用于将本地 AI 智能体零基础设施部署到 AWS 的 SDK,支持多种开源框架,提供运行时、记忆、网关、代码解释器等企业级服务。 Amazon Bedrock AgentCore SDK 1.4.8版本和1.5.0版本存在日志信息泄露漏洞,该漏洞源于OpenTelemetry instrumentation未过滤或屏蔽原始用户提示和代理响应,可能导致本地认证用户访问CloudWatch日志中的敏感数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
AWS bedrock-agentcore 1.4.8 -

II. Public POCs for CVE-2026-15737

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15737

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-15737 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15737

No comments yet


Leave a comment