216.73.216.233

CVE-2026-8838

· Published 18/05/2026 21:16 · Modified 19/05/2026 14:24

Labels: CVE-2026-8838 2026-05-18CVE-2026-8838CWE-94ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
18/05/2026 21:16
Modified
19/05/2026 14:24
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
amazon / redshift python driver cpe:2.3:a:amazon:redshift_python_driver:<2.1.14:*:*:*:*:*:*:*

References