CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
Summary
The Bedrock AgentCore Python SDK (a library for building AI agents on Amazon's platform) has a vulnerability where OpenTelemetry spans (data that tracks what a program is doing) were writing unfiltered user prompts and AI responses to CloudWatch logs (AWS's logging service). This meant that anyone with read access to those logs could see potentially sensitive information. The vulnerability affects versions 1.4.8 and 1.5.0.
Classification
Affected Vendors
Related Issues
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-058-aws/
First tracked: July 16, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%