bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, October 9, 2026

AWS Amplify API Category: Critical Authorization Bypass in Query Resolvers

AWS Amplify API Category has a nasty authorization flaw (CVE-2026-108096) in @aws-amplify/graphql-index-transformer that lets authenticated users read other users' data through crafted queries. You need to update immediately: @aws-amplify/graphql-index-transformer to 3.1.2+, @aws-amplify/graphql-api-construct to 1.21.4+, or @aws-amplify/data-construct to 1.17.4+. This is a serious data exposure risk—patch your AppSync APIs ASAP.

source: [aws/security-bulletin]