sagemaker has 8 CVEs on record between 2024 and 2026. The median CVSS is 7.2 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- sagemaker 8
Worst active — by depth score
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability43CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data43GHSA-5r2p-pjr8-7fh7HighSageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality41CVE-2026-8597High· 7.2Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler40CVE-2026-8596High· 7.2Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path40
sagemaker vulnerabilities
CVEs affecting sagemaker, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-8597High· 7.2Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
CVE-2026-8596High· 7.2Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
GHSA-5r2p-pjr8-7fh7HighSageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
CVE-2026-1777High· 7.2SageMaker Python SDK has Exposed HMAC
SageMaker Python SDK has Exposed HMAC
CVE-2026-1778Medium· 5.9SageMaker Python SDK has Insecure TLS Configuration
SageMaker Python SDK has Insecure TLS Configuration
CVE-2025-0508Medium· 5.9SageMaker Workflow component allows possibility of MD5 hash collisions
SageMaker Workflow component allows possibility of MD5 hash collisions
CVE-2024-34072High· 7.8sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
CVE-2024-34073High· 7.8sagemaker-python-sdk Command Injection vulnerability
sagemaker-python-sdk Command Injection vulnerability