bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-9291

show all
Thursday, August 20, 2026

Amazon Braket SDK Vulnerability Lets Attackers Execute Code via Job Results

Amazon Braket SDK versions 1.10.0 through 1.116.x have a nasty insecure deserialization flaw (CVE-2026-9291) in job results processing. If you've got S3 write access to the output bucket, you can swap the dataFormat field and inject malicious pickle payloads—boom, arbitrary code execution on anyone processing those results. Update to 1.117.0+ immediately if you're using this quantum computing SDK.

source: [aws/security-bulletin]