CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
Summary
Amazon SageMaker Python SDK stores HMAC keys (cryptographic secrets used to verify data hasn't been tampered with) in plain text in pipeline definitions, allowing users with DescribePipeline permissions to read these keys and inject malicious code into other users' pipeline executions within the same AWS account. The vulnerability affects SageMaker Python SDK v3 versions before v3.11.0 and v2 versions before v2.256.0.
Solution / Mitigation
Update to SageMaker Python SDK v3.11.0 or later, or update to SageMaker Python SDK v2.256.0 or later.
Classification
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/
First tracked: September 1, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%