{"id":"CVE-2026-104002","title":"A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. \n\n\n\nTo remediate this issue, users should upg…","summary":"A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. \n\n\n\nTo remediate this issue, users should upg…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-390"],"vendor":"AWS","product":"powertools-lambda-python","affected":["powertools-lambda-python >= 3.6.0 <= 3.34.0"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T22:17:00.567","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104002","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-123-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T23:03:32.766Z","slug":"CVE-2026-104002","body":"## Overview\n\nA fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. \n\n\n\nTo remediate this issue, users should upgrade to version 3.35.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}