5.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Description
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.
Basic Information
ID
CVE-2026-1778
Source
AMZN
Published
Feb 2, 2026 at 20:14
Affected Product
Vendor
AWS
Product
SageMaker Python SDK
Version
3.1.1