Improper Certificate Validation in AWS IoT Device SDK for Python
CVE-2026-92943
9.2CRITICAL
What is CVE-2026-92943?
There is an improper validation of certificates with host mismatch in the MQTT client TLS connection layer of the AWS IoT Device SDK for Python. This vulnerability affects versions 1.5.3 through 1.6.0 on Python 3.7 and later, allowing an attacker to potentially impersonate AWS IoT Core endpoints. An adversary-in-the-middle may exploit this vulnerability to read device telemetry and inject arbitrary MQTT messages that the affected device may interpret as legitimate. Users are advised to upgrade to version 1.6.1 to mitigate this risk.
Affected Version(s)
AWSIoTPythonSDK 1.5.3 <= 1.6.0
