Skip to main content

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

Bulletin ID: 2026-133-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/09/2026 11:00 AM PDT

Description:

AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.

Impacted versions:

  • @aws-amplify/graphql-index-transformer >=2.2.0, <3.1.2;
  • @aws-amplify/graphql-api-construct >=1.4.0, <1.21.4;
  • @aws-amplify/data-construct <1.17.4

Resolution:

This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 (included in @aws-amplify/data-construct 1.17.4 and @aws-amplify/graphql-api-construct 1.21.4). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.

Workarounds:

No workarounds are available.

References:


Please email aws-security@amazon.com with any security questions or concerns.