Vulnerability PYSEC-2026-1885

Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 02:34 PM UTC
SageMaker Workflow component allows possibility of MD5 hash collisions
1.0.0 - 2.237.1
1.0.0 - 2.237.1

Summary

SageMaker Workflow component allows possibility of MD5 hash collisions

Details

A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.

Impacted packages

Timeline

Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Fixed (2.237.3)
1 year ago
January 09, 2025 at 09:56 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC