PT-2026-41734 · Pypi · Amazon-Redshift-Python-Driver

Institute

·

Published

2026-05-18

·

Updated

2026-05-29

·

CVE-2026-8838

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions amazon-redshift-python-driver versions prior to 2.1.14
Description Unsafe use of Python's eval() function on data received from a server within the vector in() function allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client.
Recommendations Upgrade to version 2.1.14.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-8838
GHSA-29H4-R29X-HCHV

Affected Products

Amazon-Redshift-Python-Driver