Skip to content
TrustList
News

AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)

Editorial

By TrustList Editorial

AWS bulletins fix a mount-option injection flaw in the Amazon EFS CSI Driver for Kubernetes (versions 3.1.0 to 3.4.2, fixed in 3.5.0) and arbitrary command execution when GluonTS loads untrusted model directories (before 0.17.0).

About AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)

AWS bulletins: EFS CSI Driver mount-option injection (CVE-2026-103505, fixed in 3.5.0) and GluonTS code execution (CVE-2026-100308, fixed in 0.17.0)

1 October 2026 — AWS published two security bulletins at the end of September for open-source components used in Kubernetes and machine-learning environments. Neither affects a managed AWS service directly, but both sit in software that customers install and run themselves.

Not yet independently verified. Both sources are AWS's own bulletins; no independent report was found. AWS does not say whether either flaw has been exploited. We will update this when it can be confirmed, and remove this note.

Amazon EFS CSI Driver: CVE-2026-103505

Bulletin 2026-120-AWS, published on 1 October 2026, describes a mount-option injection flaw in the Amazon EFS CSI Driver, which lets Kubernetes clusters use Amazon Elastic File System volumes. An actor with permission to create PersistentVolumes could inject additional mount options through a volume attribute. AWS lists versions 3.1.0 to 3.4.2 as affected and 3.5.0 as fixed.

GluonTS: CVE-2026-100308

Bulletin 2026-119-AWS, published on 29 September 2026, covers GluonTS, AWS's open-source library for probabilistic time-series forecasting models. Loading an untrusted model directory could lead to arbitrary command execution during deserialisation. Versions before 0.17.0 are affected; 0.17.0 is fixed.

Who is affected

  • Teams running Kubernetes clusters, on Amazon EKS or self-managed, that use the EFS CSI Driver, especially multi-tenant clusters where users who can create PersistentVolumes are not fully trusted.
  • Data-science and ML teams using GluonTS who load models from shared storage, model hubs or other teams.

What to do

  1. Upgrade the EFS CSI Driver to 3.5.0 or later, including in Helm charts and EKS add-on configurations.
  2. Review which users and service accounts can create PersistentVolumes, and restrict it to administrators where possible.
  3. Upgrade GluonTS to 0.17.0 or later in notebooks, training images and inference containers.
  4. Load only model directories from trusted sources, and treat serialised models as code.

Why it matters for buyers

Both flaws follow familiar patterns: configuration values that can smuggle in extra options, and model files that execute code when loaded. As ML models are shared more widely, checking where models come from belongs in software supply-chain controls.

Sources

Categories & features