CVE-2026-104002EPSS p21.2%
CVE-2026-104002CVE-2026-104002
Description
A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.
To remediate this issue, users should upgrade to version 3.35.0.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.31% probability of exploitation · percentile 21.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |