bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, July 16, 2026

Bedrock AgentCore Python SDK Leaks Sensitive Data via OpenTelemetry Spans

AWS flagged CVE-2026-15737 in bedrock-agentcore versions 1.4.8 and 1.5.0—unfiltered user prompts and agent responses get logged to CloudWatch, exposing them to anyone with read access. **Action required**: upgrade immediately if you're running affected versions. Local authenticated users could snoop on your sensitive AI interactions through OpenTelemetry span attributes.

> source: aws.amazon.com