bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Tuesday, September 1, 2026

Amazon SageMaker Python SDK: Critical HMAC Key Exposure Vulnerability

Amazon SageMaker Python SDK has a serious security flaw where HMAC signing keys are stored in cleartext in pipeline definitions. Attackers with account access can extract these keys via DescribePipeline API and execute arbitrary code in other users' pipelines. Update immediately: SDK v3 to v3.11.0+ or v2 to v2.256.0+. Action required for all users running affected versions.

source: [aws/security-bulletin]