Description
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask. 



To remediate this issue, users should upgrade to version 3.35.0.
Published: 2026-10-01
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Loss of Confidentiality
Action: Immediate Patch
AI Analysis

Impact

The failure‑open logic in the data masking utility allows an attacker to read values that were intended to be hidden. This flaw can expose sensitive information in logs or responses, compromising confidentiality. The weakness is a classic fail‑safe coding issue (CWE‑390) where error handling accepts the original data instead of masking it.

Affected Systems

AWS Powertools for Lambda (Python) library before version 3.35.0. The 3.35.0 release resolves the issue, so any application using an earlier release is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6 indicates moderate risk. No exploit probability data is available, and the vulnerability is not listed in the KEV catalog. An attacker could attempt to induce an error in the masking function through crafted input or misconfigured Lambda contexts, but no public exploit has been documented. The attack requires application language access to the payload and the ability to trigger the data masking routine.

Generated by OpenCVE AI on October 1, 2026 at 22:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Powertools for Lambda (Python) version 3.35.0 to patch the fail‑open error handling flaw.
  • If an upgrade cannot be applied immediately, surround data masking calls with explicit error handling that replaces unmasked values with a safe placeholder or suppresses the output entirely.
  • Enable strict logging controls in the Lambda environment to prevent sensitive payloads from being recorded or returned in case an error occurs.

Generated by OpenCVE AI on October 1, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Description A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.  To remediate this issue, users should upgrade to version 3.35.0.
Title Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)
Weaknesses CWE-390
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-01T21:13:27.713Z

Reserved: 2026-10-01T16:20:44.923Z

Link: CVE-2026-104002

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T22:17:00.567

Modified: 2026-10-01T22:17:00.567

Link: CVE-2026-104002

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T23:00:20Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action