Executive brief
AWS Powertools for Lambda is a developer toolkit for building serverless applications on AWS. A fail-open error handling flaw in its data masking utility allows unintended exposure of sensitive fields that applications attempt to mask, potentially revealing confidential data like passwords, tokens, or personally identifiable information to attackers or unauthorized users.
Technical details
The data masking utility in Powertools for Lambda (Python) contains a fail-open vulnerability where masking errors return the original unmasked value instead of raising an exception, allowing sensitive field values to be exposed. This affects versions 3.6.0 through 3.34.0 and is resolved in version 3.35.0, which raises a DataMaskingError exception on masking failures. The vulnerability requires the application to use the masking utility but introduces no special authentication or network preconditions beyond normal library usage.
Affected products
- AWS Powertools for Lambda (Python) >=3.6.0, <3.35.0
Timeline
- 2026-10-01: disclosed
- 2026-10-01: patched: Fixed in version 3.35.0