AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)
EditorialBy TrustList Editorial
AWS bulletins fix a mount-option injection flaw in the Amazon EFS CSI Driver for Kubernetes (versions 3.1.0 to 3.4.2, fixed in 3.5.0) and arbitrary command execution when GluonTS loads untrusted model directories (before 0.17.0).
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- +2 more
About AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)
AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)
1 October 2026 — AWS published two security bulletins at the end of September for open-source components used in Kubernetes and machine-learning environments. Neither affects a managed AWS service directly, but both sit in software that customers install and run themselves.
Not yet independently verified. Both sources are AWS's own bulletins; no independent report was found. AWS does not say whether either flaw has been exploited. We will update this when it can be confirmed, and remove this note.
Amazon EFS CSI Driver: CVE-2026-103505
Bulletin 2026-120-AWS, published on 1 October 2026, describes a mount-option injection flaw in the Amazon EFS CSI Driver, which lets Kubernetes clusters use Amazon Elastic File System volumes. An actor with permission to create PersistentVolumes could inject additional mount options through a volume attribute. AWS lists versions 3.1.0 to 3.4.2 as affected and 3.5.0 as fixed.
GluonTS: CVE-2026-100308
Bulletin 2026-119-AWS, published on 29 September 2026, covers GluonTS, AWS's open-source library for probabilistic time-series forecasting models. Loading an untrusted model directory could lead to arbitrary command execution during deserialisation. Versions before 0.17.0 are affected; 0.17.0 is fixed.
Who is affected
- Teams running Kubernetes clusters, on Amazon EKS or self-managed, that use the EFS CSI Driver, especially multi-tenant clusters where users who can create PersistentVolumes are not fully trusted.
- Data-science and ML teams using GluonTS who load models from shared storage, model hubs or other teams.
What to do
- Upgrade the EFS CSI Driver to 3.5.0 or later, including in Helm charts and EKS add-on configurations.
- Review which users and service accounts can create PersistentVolumes, and restrict it to administrators where possible.
- Upgrade GluonTS to 0.17.0 or later in notebooks, training images and inference containers.
- Load only model directories from trusted sources, and treat serialised models as code.
Why it matters for buyers
Both flaws follow familiar patterns: configuration values that can smuggle in extra options, and model files that execute code when loaded. As ML models are shared more widely, checking where models come from belongs in software supply-chain controls.
Sources
Categories & features
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- Container Management
- Machine Learning
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.