CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
Amazon SageMaker ยท 2026-09-09
Actions
Technical Details
| Affected Versions | v3 < v3.11.0, v2 < v2.256.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-83551 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update Amazon SageMaker Python SDK to version 3.11.0 or 2.256.0 to address the security vulnerability (CVE-2026-83551) and ensure the integrity of serialized function payloads by replacing symmetric HMAC signing with asymmetric ECDSA signing.
For Platform Teams
Adopt the updated Amazon SageMaker Python SDK to enhance the security of your AI/ML pipelines by mitigating the risk associated with cleartext storage of HMAC keys.
For Executives
Implement the latest Amazon SageMaker Python SDK updates to mitigate the risk of unauthorized code execution due to cleartext storage of HMAC keys, ensuring the integrity and security of your AI/ML pipelines.
Source
Related Amazon SageMaker Updates
- Amazon SageMaker Feature Store introduces UpdateRecord for feature-level writes (2026-09-08)
- Amazon SageMaker Feature Store now supports individual feature updates to lower write latency (2026-09-08)
- Amazon SageMaker AI Batch Transform now supports G6e instances (2026-09-04)
- Amazon SageMaker Unified Studio Workflows support Python and Bash operators (2026-09-03)
- Amazon SageMaker Unified Studio CI/CD adds notebook promotion and AI-assisted manifest generation (2026-09-02)