CVE-2026-107608: Improper link resolution in asset bundling output handling in aws-cdk-lib
Bulletin ID: 2026-131-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 12:30 PM PDT
Description:
AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation. We identified CVE-2026-107608, which is an issue where Docker files could be configured to insert symlinked files into the output of the AWS CDK asset bundling process when it was invoked with a Docker file. When bundling an asset using AWS CDK with a docker file, prior to 2.267.0, it was possible for a docker file to insert a symlinked file or directory into the output of asset bundling without the symlink having been provided as input to the bundling process.
Impacted versions: All aws-cdk-lib versions before 2.267.0
Resolution:
This issue has been addressed in aws-cdk-lib version 2.267.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
If you cannot immediately upgrade, you can reduce the possibility of streaming unexpected information by auditing all Docker bundling containers and their dependencies to confirm that no untrusted code executes inside the configured bundling environment.
References:
Please email aws-security@amazon.com with any security questions or concerns.