MEDIUM 6.0 NVD
CVE-2026-104002
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that th
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.
To remediate this issue, users should upgrade to version 3.35.0.
References
- https://aws.amazon.com/security/security-bulletins/2026-123-aws/
- https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0
- https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4
This medium severity vulnerability with a CVSS score of 6.0 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9442 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.