Amazon SageMaker Python SDK: Critical Model Artifact Vulnerabilities Require Immediate Patching
Amazon SageMaker Python SDK versions 2.199.0–2.257.1 and 3.0.0–3.7.1 have two nasty security flaws (CVE-2026-8596 & CVE-2026-8597) that could let authenticated attackers execute code on your inference containers. The first exposes HMAC signing keys in plaintext through AWS APIs, while the second skips integrity checks on model artifacts entirely. If you're running affected versions with S3 access, you need to update immediately—this is a remote code execution risk.
source: [aws/security-bulletin]