AWS CDK fixes a symlink flaw in Docker asset bundling in 2.267.0
EditorialBy TrustList Editorial
Every aws-cdk-lib release before 2.267.0 is affected, and the bulletin offers an audit-your-containers workaround for teams that cannot upgrade immediately. AWS does not state a severity score.
About AWS CDK fixes a symlink flaw in Docker asset bundling in 2.267.0
AWS CDK fixes a symlink flaw in Docker asset bundling in 2.267.0
8 October 2026: Amazon Web Services has fixed CVE-2026-107608 in aws-cdk-lib, the construct library behind the AWS Cloud Development Kit. The flaw lets a Dockerfile used for asset bundling place a symbolic link in the bundling output even though that link was never supplied as input, and it affects every version before 2.267.0. AWS lists the fix as 2.267.0 and rates the bulletin "Important", without giving a CVSS score or saying whether anyone is exploiting it.
Not yet independently verified. The bulletin gives no CVSS score and does not say whether the flaw is exploited. Both figures are left out until AWS or the linked GitHub advisory states them. We will update this when it can be confirmed, and remove this note.
The bulletin is numbered 2026-131-AWS and describes the bug as improper link resolution in how the output of asset bundling is handled. In practice it matters to teams that build assets such as Lambda packages or container contexts inside Docker during cdk synth and cdk deploy, because the bundling container is the place where the stray link can appear.
Fixed version and workaround
The remedy is to upgrade aws-cdk-lib to 2.267.0 or later. AWS also asks anyone who maintains a fork or derivative of the library to apply the same patch to that code.
For teams that cannot upgrade immediately, the bulletin gives one workaround: audit every Docker bundling container and its dependencies, and confirm that no untrusted code runs in the bundling environment. The risk therefore depends on what your build pulls in. A pipeline that bundles only first-party code from pinned base images sits in a different position from one that installs packages at build time from public registries.
Where to look in your own pipelines
Search your CDK projects for bundling options that use Docker, whether through asset bundling settings or custom Dockerfiles, and check which version of aws-cdk-lib each project pins in its lock file. Shared build images and CI runners deserve the same check, because one stale version there can undo upgrades made in individual repositories.
The bulletin links to the CVE record and to GitHub advisory GHSA-h6j4-qpp7-q28p. Our DevOps software category lists 15 products that cover build and deployment automation.
Related on TrustList:
- Docker Engine 29.8.2 fixes DNS trick that disables TLS checks
- AWS: Powertools for AWS Lambda (Python) data masking could fail open, and three more AWS libraries need updates
Sources
Categories & features
- AWS
- DevOps
- Docker
- Cybersecurity
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More AWSThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.