Skip to main content

CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

Bulletin ID: 2026-123-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/01/2026 14:00 PM PDT

Description:

Powertools for AWS Lambda (Python) is a developer toolkit that implements serverless best practices and increases developer velocity. We identified CVE-2026-104002, a fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python). This issue might allow actors to read sensitive field values that the application intended to mask.

Impacted versions:  >=3.6.0 AND <=3.34.0

Resolution:

This issue has been addressed in Powertools for AWS Lambda (Python) version 3.35.0. Masking errors now raise a DataMaskingError exception instead of returning the original value. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

There is no workaround available.

References:


Please email aws-security@amazon.com with any security questions or concerns.