CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands

Cli Emr ยท 2026-09-09

Actions

Rate this issue

Technical Details

Affected Versions AWS CLI v1 <= 1.45.27, AWS CLI v2 <= 2.35.2
Regions all
CVE IDs CVE-2026-18654
Migration Required Yes
Cost Impact Neutral

What This Means

For DevOps Teams

Update AWS CLI to versions 1.45.28 or 2.35.3 to resolve the security vulnerability CVE-2026-18654 and ensure secure SSH connections to EMR clusters.

For Platform Teams

Deploy the latest AWS CLI versions to incorporate the security fixes for CVE-2026-18654 and maintain secure operations for EMR clusters.

For Executives

Implement immediate upgrades to AWS CLI to address CVE-2026-18654 and mitigate security risks associated with EMR clusters.

Source

View original AWS announcement โ†’

Related Cli Emr Updates

Weekly AWS Digest in Your Inbox

No spam, no headlines. Just a weekly summary of the 3โ€“7 AWS changes that matter for DevOps and Platform teams.

๐Ÿ“ง Exactly 1 email per week โ€ข Every Tuesday โ€ข Unsubscribe anytime

Today: AWS only. Coming next: Azure and other major clouds.