Bedrock AgentCore Python SDK Leaks Sensitive Data via OpenTelemetry Spans
AWS flagged CVE-2026-15737 in bedrock-agentcore versions 1.4.8 and 1.5.0—unfiltered user prompts and agent responses get logged to CloudWatch, exposing them to anyone with read access. **Action required**: upgrade immediately if you're running affected versions. Local authenticated users could snoop on your sensitive AI interactions through OpenTelemetry span attributes.