Junglewise Threat Intelligence

CVE-2026-104002: AWS Powertools for Lambda (Python) data masking fail-open error handling

CVE-2026-104002 · Severity: high · Published 2026-10-01

Technologies: Amazon AWS. Vendors: AWS, Amazon.

Executive brief

AWS Powertools for Lambda is a developer toolkit for building serverless applications on AWS. A fail-open error handling flaw in its data masking utility allows unintended exposure of sensitive fields that applications attempt to mask, potentially revealing confidential data like passwords, tokens, or personally identifiable information to attackers or unauthorized users.

Technical details

The data masking utility in Powertools for Lambda (Python) contains a fail-open vulnerability where masking errors return the original unmasked value instead of raising an exception, allowing sensitive field values to be exposed. This affects versions 3.6.0 through 3.34.0 and is resolved in version 3.35.0, which raises a DataMaskingError exception on masking failures. The vulnerability requires the application to use the masking utility but introduces no special authentication or network preconditions beyond normal library usage.

Affected products

  • AWS Powertools for Lambda (Python) >=3.6.0, <3.35.0

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: patched: Fixed in version 3.35.0

References

Related threats