CVE-2025-0508Medium· 5.9▾ SunlitSageMaker Workflow component allows possibility of MD5 hash collisions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.3%
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.
sagemaker < 2.237.3Upgrade to a patched release:
sagemaker 2.237.3Connected by shared product, vendor, weakness, or advisory.
GHSA-5r2p-pjr8-7fh7HighSageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
CVE-2026-8597High· 7.2Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
CVE-2026-8596High· 7.2Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
CVE-2026-1777High· 7.2SageMaker Python SDK has Exposed HMAC
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability