PT-2026-60522 · Aws · Bedrock Agentcore Python Sdk

CVE-2026-15737

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AWS Bedrock AgentCore Python SDK versions 1.4.8 through 1.5.0
Description OpenTelemetry instrumentation in the SDK causes unintended logging of sensitive user content. The library writes raw user prompts and complete agent responses into OpenTelemetry span attributes during every invocation without filtering or masking. These spans are sent to the aws/spans CloudWatch log group, potentially allowing a local authenticated user with log read access to view sensitive data.
Recommendations Upgrade to version 1.5.1 or later. Review and purge sensitive content from aws/spans CloudWatch log groups.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15737
GHSA-HQF8-7W95-9R33

Affected Products

Bedrock Agentcore Python Sdk