{"id":"CVE-2026-8838","title":"Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client","summary":"Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. \n\n\n\nTo remediate t…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-94"],"published":"2026-05-18","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-8838","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-033-aws/","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-29h4-r29x-hchv","label":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8838"},{"url":"https://github.com/aws/amazon-redshift-python-driver/commit/69a69dfdead75918e20384da52bcd760ded8dbca"},{"url":"https://aws.amazon.com/security/security-bulletins/2026-033-aws"},{"url":"https://github.com/aws/amazon-redshift-python-driver"}],"tags":["nvd","exploit-available","osv","pip"],"epss":0.00808,"epssPercentile":0.55343,"ingestedAt":"2026-07-23T20:19:18.693Z","exploits":{"github":2,"githubRepos":["https://github.com/Maxime288/CVE-2026-8838-RCE","https://github.com/Sana-404/CVE-2026-8838-Mitigation-and-Detection"],"checkedAt":"2026-09-23T07:15:12.466Z"},"exploitAvailable":true,"aliases":["GHSA-29h4-r29x-hchv","PYSEC-2026-521"],"ecosystem":"pip","vendor":"redshift-connector","product":"redshift-connector","affected":["redshift-connector < 2.1.14"],"patched":["redshift-connector 2.1.14"],"slug":"CVE-2026-8838","body":"## Overview\n\nUnsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. \n\n\n\nTo remediate this issue, users should upgrade to version 2.1.14.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-8838)\n\nAffected packages:\n\n- `redshift-connector < 2.1.14`\n\nPatched in:\n\n- `redshift-connector 2.1.14`\n\nSource: https://osv.dev/vulnerability/GHSA-29h4-r29x-hchv","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5540,"id":"CVE-2026-8838","ts":1788887298394,"field":"exploit_available","old":"false","new":"true"},{"seq":4415,"id":"CVE-2026-8838","ts":1788886404878,"field":"exploit_available","old":"true","new":"false"},{"seq":3128,"id":"CVE-2026-8838","ts":1788883069675,"field":"exploit_available","old":"false","new":"true"},{"seq":2157,"id":"CVE-2026-8838","ts":1788882472739,"field":"exploit_available","old":"true","new":"false"},{"seq":1186,"id":"CVE-2026-8838","ts":1788881909560,"field":"exploit_available","old":"false","new":"true"}]}