Intel

AIKIDO-2026-158758

aws-lambda-powertools is vulnerable to Information Disclosure

Information DisclosureCVE-2026-104002 Published Yesterday

53

Medium Risk

This Affects:

PYTHONaws-lambda-powertools
3.6.0 - 3.34.0
Fixed in 3.35.0
Are you affected? Scan for Free

TL;DR

The DataMasking.erase helper in the data masking utility catches invalid masking expressions and provider errors and returns the original field value instead of failing. An invalid regular expression in the masking configuration or an exception raised by a custom provider's erase implementation triggers this path silently. Applications that treat the result as masked can then write the unmasked sensitive field to a downstream destination such as CloudWatch Logs or S3. The patch raises DataMaskingError on these failures instead of returning the original value.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the data masking utility's erase method with a masking expression or a custom provider that can raise an error.

Background info

aws-lambda-powertools is vulnerable to Information Disclosure in versions 3.6.0 - 3.34.0.

How to fix this

Upgrade the aws-lambda-powertools library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform