CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.
To remediate this issue, users should upgrade to version 3.35.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Powertools for AWS Lambda (Python)to a version that resolves this vulnerability.Fixed in 3.35.0
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker needs network access and low-level privileges. Exploitation also has high complexity and does not require user interaction.
What data could be exposed?
Sensitive field values that the application intended to mask may be readable when the data masking utility encounters the fail-open error condition. The issue affects confidentiality; no integrity or availability impact is specified.
What should teams do to remediate this issue?
Upgrade Powertools for AWS Lambda (Python) to version 3.35.0.