PT-2026-41734 · Pypi · Amazon-Redshift-Python-Driver

·

CVE-2026-8838

·

Published

2026-05-18

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions amazon-redshift-python-driver versions prior to 2.1.14
Description Unsafe use of Python's eval() function on data received from a server within the vector in() function allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client.
Recommendations Upgrade to version 2.1.14.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-8838
ECHO-6DE6-5CA5-2794
GHSA-29H4-R29X-HCHV
PYSEC-2026-521

Affected Products

Amazon-Redshift-Python-Driver