CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
AWS ยท 2026-07-16
Actions
Technical Details
| Affected Versions | 1.4.8, 1.5.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-15737 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update Bedrock AgentCore Python SDK to version 1.5.1 or later to address CVE-2026-15737 and prevent sensitive content disclosure in OpenTelemetry spans.
For Platform Teams
Deploy the patched Bedrock AgentCore Python SDK to ensure that sensitive content is no longer exposed in OpenTelemetry spans, enhancing overall platform security.
For Executives
Implement the upgrade to Bedrock AgentCore Python SDK version 1.5.1 or later to mitigate the risk of sensitive content disclosure and ensure compliance with security standards.