AWS SageMaker Python SDK: Two Critical Security Flaws Require Immediate Updates
AWS SageMaker Python SDK has two nasty vulnerabilities you need to patch ASAP. CVE-2026-1777 exposes HMAC secret keys in environment variables via the DescribeTrainingJob API, letting attackers forge malicious payloads and overwrite S3 objects. CVE-2026-1778 disables SSL verification globally, affecting all HTTPS connections when using the Triton Python backend. Update to v3.2.0+ or v2.256.0+ immediately—user action is required.
source: [aws/security-bulletin]