A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. To remediate this issue, users should upgrade to version 3.35.0.
https://github.com/aws-powertools/powertools-lambda-python/security/advisories/GHSA-3vxg-4xv2-jfh5
https://github.com/aws-powertools/powertools-lambda-python/releases/tag/v3.35.0
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-91063
https://aws.amazon.com/security/security-bulletins/2026-123-aws/
Published: 2026-10-01
Updated: 2026-10-02
Base Score: 4.9
Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity: Medium
Base Score: 6
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity: Medium
EPSS: 0.00306