CVE-2026-104002
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
- Published Oct 1, 2026
- CVSS 6.0 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available