bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: Amazon SageMaker Python SDK

show all
Thursday, August 20, 2026

Amazon SageMaker Python SDK: Critical Model Artifact Vulnerabilities Require Immediate Patching

Amazon SageMaker Python SDK versions 2.199.0–2.257.1 and 3.0.0–3.7.1 have two nasty security flaws (CVE-2026-8596 & CVE-2026-8597) that could let authenticated attackers execute code on your inference containers. The first exposes HMAC signing keys in plaintext through AWS APIs, while the second skips integrity checks on model artifacts entirely. If you're running affected versions with S3 access, you need to update immediately—this is a remote code execution risk.

source: [aws/security-bulletin]