In plain language
What this advisory means
A security issue was found in the data masking feature of the Powertools for AWS Lambda (Python) toolkit. This flaw could let someone see sensitive information that the application meant to hide. Amazon fixed this in a newer version and recommends users upgrade.
Technical explanation
How the issue affects the environment
CVE-2026-104002 is a fail-open error handling vulnerability in the data masking utility of Powertools for AWS Lambda (Python). When masking errors occur, the utility returned the original sensitive value instead of masking it, potentially exposing sensitive data fields. The issue affects versions 3.6.0 and above. The vendor fixed this by modifying the utility to raise a DataMaskingError exception on errors rather than returning unmasked data, implemented in version 3.35.0.
Operational impact
Why teams should care
Sensitive data intended to be masked by the application could be inadvertently exposed, increasing the risk of data breaches, regulatory non-compliance, and reputational damage. This could affect any organization using the vulnerable versions of Powertools for AWS Lambda (Python) that rely on data masking for privacy or compliance.
Immediate action
Upgrade Powertools for AWS Lambda (Python) to version 3.35.0 or later, which changes error handling to raise a DataMaskingError instead of returning unmasked data. Also review any forks or derivative code to incorporate these fixes.
Affected and fixed releases
Temporary risk reduction
There is no workaround available for this issue. Users must upgrade to the patched version to remediate the vulnerability.
Evidence and validation checklist
- AWS Security Bulletins official publication detailing CVE-2026-104002
- Description of fail-open error handling mechanism in the data masking utility
- Version impacted (>=3.6.0) and fixed version (3.35.0) stated
- No workaround available as per bulletin
- Remediation instructions to upgrade to fixed version
- No mention of exploitation or severity rating
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
