Intel

AIKIDO-2026-10901

redshift_connector is vulnerable to Code Injection

Code InjectionCVE-2026-8838 Published 6 days ago

98

Critical Risk

This Affects:

PYTHONredshift_connector
0.0.1 - 2.1.13
Fixed in 2.1.14
Are you affected? Scan for Free

TL;DR

Affected versions are vulnerable to an input validation flaw in amazon-redshift-python-driver query result processing. A rogue server or man-in-the-middle attacker could send crafted PostgreSQL protocol responses that may lead to arbitrary code execution on the client, potentially allowing command execution, file access, or credential theft.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

redshift_connector is vulnerable to Code Injection in versions 0.0.1 - 2.1.13.

How to fix this

Upgrade the redshift_connector library to the patch version.