9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client.
To remediate this issue, users should upgrade to version 2.1.14.
To remediate this issue, users should upgrade to version 2.1.14.
AI Analysis
Remote code execution via eval() injection in amazon-redshift-python-driver
Basic Information
ID
CVE-2026-8838
Source
AMZN
Published
May 18, 2026 at 20:15
Modified
May 18, 2026 at 20:19
Affected Product
Vendor
AWS
Product
Amazon Redshift connector for Python
Affected Versions
AWS Amazon Redshift connector for Python 0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Amazon Web Services (AWS)
Product
Amazon Redshift connector for Python
Version
< 2.1.14