CVE-2026-104002

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,0
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM 5,3
Source: ff89ba41-3aa1-4d27-914a-91399e9639e5
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none

Description

AI Translation Available

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. 

To remediate this issue, users should upgrade to version 3.35.0.

390

Detection of Error Condition Without Action

Draft
Common Consequences
Security Scopes Affected:
Integrity Other
Potential Impacts:
Varies By Context Unexpected State Alter Execution Logic
Applicable Platforms
All platforms may be affected
View CWE Details
https://aws.amazon.com/security/security-bulletins/2026-123-aws/
https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0
https://github.com/aws-powertools/powertools-lambda-python/security/advisories/…