// Alert

AWS threat report

// AWSHIGH

CVE-2026-83551 in AWS SageMaker Python SDK before v3.11.0 and v2.256.0 stores HMAC signing keys in cleartext within pipeline decorator components. Authenticated remote users can extract keys from DescribePipeline API responses and forge valid signatures for malicious function payloads, achieving code execution in another user's pipeline execution context within the same AWS account.

// Get alerts for AWS