Data Masking Security Flaw in Powertools for AWS Lambda by Amazon
CVE-2026-104002

6MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
1 October 2026

What is CVE-2026-104002?

A fail-open error handling vulnerability within the data masking utility of Powertools for AWS Lambda (Python) may permit unauthorized actors to access sensitive field values that the application is designed to hide. This could lead to unintended exposure of confidential data. Users are strongly advised to update to version 3.35.0 to mitigate this risk and enhance their application's security.

Affected Version(s)

powertools-lambda-python 3.6.0 <= 3.34.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.