Integrity Verification Flaw in Amazon SageMaker Python SDK by AWS
CVE-2026-8597

6.4MEDIUM

What is CVE-2026-8597?

A vulnerability in the Triton inference handler of Amazon SageMaker Python SDK allows remote authenticated users to execute arbitrary code within inference containers. This occurs when model artifacts in S3 are replaced with maliciously crafted pickle payloads that are deserialized without adequate verification. To mitigate this risk, users must upgrade to Amazon SageMaker Python SDK v2.257.2 or v3.8.0 and reconstruct any existing Triton models utilizing the updated SDK.

Affected Version(s)

AWS 2.199.0 <= 2.257.1

AWS 3.0.0 <= 3.7.1

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.