Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

A security issue was found in the data masking feature of the Powertools for AWS Lambda (Python) toolkit. This flaw could let someone see sensitive information that the application meant to hide. Amazon fixed this in a newer version and recommends users upgrade.

QCS published 2/10/2026, 8:51:41 am ISTVendor disclosure 2/10/2026, 2:45:48 am ISTVerified 2/10/2026, 8:51:41 am ISTRevision 1

In plain language

What this advisory means

A security issue was found in the data masking feature of the Powertools for AWS Lambda (Python) toolkit. This flaw could let someone see sensitive information that the application meant to hide. Amazon fixed this in a newer version and recommends users upgrade.

Technical explanation

How the issue affects the environment

CVE-2026-104002 is a fail-open error handling vulnerability in the data masking utility of Powertools for AWS Lambda (Python). When masking errors occur, the utility returned the original sensitive value instead of masking it, potentially exposing sensitive data fields. The issue affects versions 3.6.0 and above. The vendor fixed this by modifying the utility to raise a DataMaskingError exception on errors rather than returning unmasked data, implemented in version 3.35.0.

Operational impact

Why teams should care

Sensitive data intended to be masked by the application could be inadvertently exposed, increasing the risk of data breaches, regulatory non-compliance, and reputational damage. This could affect any organization using the vulnerable versions of Powertools for AWS Lambda (Python) that rely on data masking for privacy or compliance.

Immediate action

Upgrade Powertools for AWS Lambda (Python) to version 3.35.0 or later, which changes error handling to raise a DataMaskingError instead of returning unmasked data. Also review any forks or derivative code to incorporate these fixes.

Affected and fixed releases

Affected versions>=3.6.0
Fixed versions3.35.0

Temporary risk reduction

There is no workaround available for this issue. Users must upgrade to the patched version to remediate the vulnerability.

Evidence and validation checklist

  • AWS Security Bulletins official publication detailing CVE-2026-104002
  • Description of fail-open error handling mechanism in the data masking utility
  • Version impacted (>=3.6.0) and fixed version (3.35.0) stated
  • No workaround available as per bulletin
  • Remediation instructions to upgrade to fixed version
  • No mention of exploitation or severity rating

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source