CVE-2026-104002
Received Received - Intake

Data Masking Bypass in Powertools for AWS Lambda

Vulnerability report for CVE-2026-104002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: AMZN

Description

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.Β  To remediate this issue, users should upgrade to version 3.35.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
aws powertools_for_aws_lambda 3.35.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-390 The product detects a specific error, but takes no actions to handle the error.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a fail-open error handling issue in the data masking utility of Powertools for AWS Lambda (Python). It allows actors to read sensitive field values that the application intended to mask.

Detection Guidance

Detection involves checking the version of Powertools for AWS Lambda (Python) in use. Compare it against version 3.35.0. If your version is older, the system is vulnerable.

Impact Analysis

This vulnerability could lead to unauthorized access to sensitive data that was supposed to be masked, potentially exposing confidential information.

Compliance Impact

This vulnerability could lead to unauthorized exposure of sensitive data due to improper masking, which may violate GDPR's data protection principles or HIPAA's confidentiality requirements if such data is protected under those regulations.

Mitigation Strategies

Upgrade Powertools for AWS Lambda (Python) to version 3.35.0 or later to address the fail-open error handling issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart