CVE-2026-104002
Received
Received - Intake
Data Masking Bypass in Powertools for AWS Lambda
Vulnerability report for CVE-2026-104002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-01
Last updated on: 2026-10-01
Assigner: AMZN
Description
Description
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.Β
To remediate this issue, users should upgrade to version 3.35.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aws | powertools_for_aws_lambda | 3.35.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-390 | The product detects a specific error, but takes no actions to handle the error. |