AWS IoT Device SDK for Python: Certificate Validation Flaw Requires Immediate Update
AWS IoT Device SDK for Python versions 1.5.3–1.6.0 on Python 3.7+ have a critical certificate validation bug (CVE-2026-92943). An attacker on your network could intercept MQTT connections to AWS IoT Core, steal device telemetry, and inject fake messages. Both X.509 and WebSocket authentication paths are affected. Action required: upgrade to the patched version immediately if you're running vulnerable versions.
source: [aws/security-bulletin]