Data Exposure Vulnerability in Amazon SageMaker Python SDK
CVE-2026-1777
What is CVE-2026-1777?
The Amazon SageMaker Python SDK prior to version 3.2.0 and v2.256.0 contains a vulnerability where the ModelBuilder HMAC signing key is exposed in the cleartext response elements of the DescribeTrainingJob function. This exposure can allow an unauthorized third party, having permissions to invoke this API and to modify objects in the associated Training Jobs S3 output location, to upload malicious artifacts that could be executed during the subsequent invocation of the training job, potentially compromising the integrity of the training workflow.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SageMaker Python SDK 3.2.0
SageMaker Python SDK 2.256.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
