Vulnerability PYSEC-2026-1885
Medium Risk
MEDIUM RISK
CVSS Score: 5.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 07, 2026 at 02:34 PM UTC
SageMaker Workflow component allows possibility of MD5 hash collisions
1.0.0 - 2.237.1
1.0.0 - 2.237.1
Summary
SageMaker Workflow component allows possibility of MD5 hash collisions
Details
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 months ago
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
2.199.0 - 2.257.1 and 3.0 - 3.7.1 PYSEC-2026-3059
2.199.0 - 2.257.1 and 3.0 - 3.7.1 PYSEC-2026-3059
High Risk
2 months ago
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
2.199.0 - 2.257.1 and 3.0 - 3.7.1 PYSEC-2026-3060
2.199.0 - 2.257.1 and 3.0 - 3.7.1 PYSEC-2026-3060
Medium Risk
2 months ago
SageMaker Python SDK has Insecure TLS Configuration
1.0.0 - 2.255.0 and 3.0 - 3.1.0 PYSEC-2026-1886
1.0.0 - 2.255.0 and 3.0 - 3.1.0 PYSEC-2026-1886
High Risk
2 months ago
SageMaker Python SDK has Exposed HMAC
1.0.0 - 2.255.0 and 3.0 - 3.1.1 PYSEC-2026-1888
1.0.0 - 2.255.0 and 3.0 - 3.1.1 PYSEC-2026-1888
High Risk
2 months ago
sagemaker-python-sdk Command Injection vulnerability
1.0.0 - 2.214.2 PYSEC-2026-1887
1.0.0 - 2.214.2 PYSEC-2026-1887
Impacted packages
Timeline
Published
2 months ago
July 07, 2026 at 02:34 PM UTC
Fixed (2.237.3)
1 year ago
January 09, 2025 at 09:56 PM UTC
Last Modified
2 months ago
July 07, 2026 at 05:47 PM UTC