---
id: CVE-2026-104002
title: "A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.\_\n\n\n\nTo remediate this issue, users should upg…"
summary: "A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.\_\n\n\n\nTo remediate this issue, users should upg…"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-390
vendor: AWS
product: powertools-lambda-python
affected:
  - powertools-lambda-python >= 3.6.0 <= 3.34.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:00.567'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104002'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-123-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T23:03:32.766Z'
---

## Overview

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. 



To remediate this issue, users should upgrade to version 3.35.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
