CVE-2026-104002: Aws Powertools-Lambda-Python
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
Affected products
- Aws Powertools-Lambda-Python: from 3.6.0, up to and including 3.34.0
Published 2026-10-01. Last modified 2026-10-02.