Skip to content
TrustList
News

AWS: Powertools for AWS Lambda (Python) data masking could fail open, and three more AWS libraries need updates

Editorial

By TrustList Editorial

AWS bulletins of 29 September and 1 October 2026: Powertools for AWS Lambda (Python) 3.6.0 to 3.34.0 could return unmasked values on error (fixed in 3.35.0, no workaround), plus fixes for Amazon Ion Python, security-agent-mcp-server and GluonTS.

About AWS: Powertools for AWS Lambda (Python) data masking could fail open, and three more AWS libraries need updates

AWS: Powertools for AWS Lambda (Python) data masking could fail open, and three more AWS libraries need updates

2 October 2026 — Amazon Web Services published four security bulletins for open-source libraries it maintains on 29 September and 1 October 2026. None is a flaw in an AWS service itself; all four are in code that customers install in their own applications, so AWS cannot fix them for you.

Not yet independently verified. This rests on AWS’s own bulletins; no independent report was checked, and AWS gave no severity score for any of them. We read the Powertools bulletin in full and the other three through their summaries. We will update this when it can be confirmed, and remove this note.

Powertools for AWS Lambda (Python): masking that fails open

CVE-2026-104002. Powertools is a widely used toolkit for Lambda functions, and its data-masking utility is meant to hide sensitive fields, such as card numbers or personal data, before they are logged or passed on. In versions 3.6.0 to 3.34.0, an error during masking could return the original value instead of failing. AWS says this "might allow actors to read sensitive field values that the application intended to mask". It is fixed in 3.35.0, where masking errors now raise a DataMaskingError. AWS says "there is no workaround available".

This matters for compliance as much as security: if masked values ended up in logs, those logs may now hold personal or payment data that your records say they do not.

Three more libraries

  • Amazon Ion Python before 0.15.0 (CVE-2026-104020): a deeply nested Ion value can exhaust recursion in the reader and crash the application, a denial of service. Fixed in 0.15.0; until then AWS describes disabling the C extension and handling RecursionError.
  • security-agent-mcp-server 0.1.1 up to 0.2.0 (CVE-2026-97662): argument injection in the diff scan can create, overwrite or truncate files outside the workspace. Fixed in 0.2.0; meanwhile scan only trusted repositories and run the server with minimal privileges. It is an MCP server that AI coding agents call, so it often runs with a developer's own permissions.
  • GluonTS before 0.17.0 (CVE-2026-100308): loading an untrusted model artifact with Predictor.deserialize() can run operating-system commands. Fixed in 0.17.0; load only artifacts you trust.

What to do

  • Search dependency files (requirements, lock files, Lambda layers) for aws-lambda-powertools, amazon.ion, the security agent MCP server and gluonts, and bump them.
  • Rebuild and redeploy Lambda layers that bundle Powertools: updating the package locally does not change functions already deployed.
  • Review logs written by functions that used data masking on affected versions, and treat any unmasked sensitive data you find as an incident under your data-protection process.
  • Treat MCP servers as privileged software: pin versions and review what they can touch.

Sources

Categories & features