{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-104002", "assignerOrgId": "ff89ba41-3aa1-4d27-914a-91399e9639e5", "state": "PUBLISHED", "assignerShortName": "AMZN", "dateReserved": "2026-10-01T16:20:44.923Z", "datePublished": "2026-10-01T21:05:55.109Z", "dateUpdated": "2026-10-09T16:32:36.589Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "ff89ba41-3aa1-4d27-914a-91399e9639e5", "shortName": "AMZN", "dateUpdated": "2026-10-09T16:32:36.589Z" }, "title": "Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-390", "description": "CWE-390 Detection of error condition without action", "type": "CWE" } ] } ], "affected": [ { "vendor": "AWS", "product": "powertools-lambda-python", "versions": [ { "status": "affected", "version": "3.6.0", "lessThanOrEqual": "3.34.0", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "cpeApplicability": [ { "operator": "OR", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:aws:powertools-lambda-python:*:*:*:*:*:*:*:*", "versionStartIncluding": "3.6.0", "versionEndIncluding": "3.34.0" } ] } ] } ], "descriptions": [ { "lang": "en", "value": "A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. \n\n\n\nTo remediate this issue, users should upgrade to version 3.35.0.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.
To remediate this issue, users should upgrade to version 3.35.0.
" } ] } ], "references": [ { "url": "https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0", "tags": [ "patch" ] }, { "url": "https://aws.amazon.com/security/security-bulletins/2026-123-aws/", "tags": [ "vendor-advisory" ] }, { "url": "https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5", "tags": [ "third-party-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseSeverity": "MEDIUM", "baseScore": 5.3, "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "PRESENT", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 6, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 0.5.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-02T18:25:33.821951Z", "id": "CVE-2026-104002", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-02T18:25:47.226Z" } } ] } }