Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-5r2p-pjr8-7fh7
  • PyPI/sagemaker
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality 05 Mar
  • Fix available
  • Severity - 8.4 (High)
GHSA-rjrp-m2jw-pv9c
  • PyPI/sagemaker
SageMaker Python SDK has Exposed HMAC 02 Feb
  • Fix available
  • Severity - 8.7 (High)
GHSA-62rc-f4v9-h543
  • PyPI/sagemaker
SageMaker Python SDK has Insecure TLS Configuration 02 Feb
  • Fix available
  • Severity - 8.7 (High)
MAL-2025-191680
  • PyPI/amzn-sagemaker-studio
Malicious code in amzn-sagemaker-studio (PyPI) 07 Sep 2025
  • No fix available
GHSA-32g6-mg92-ghm2
  • PyPI/sagemaker
SageMaker Workflow component allows possibility of MD5 hash collisions 20 Mar 2025
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-635v-pc42-fr74
  • PyPI/sagemaker-training
AWS SageMaker Training Toolkit logs CodeArtifact Authorization token 11 Sep 2024
  • Fix available
  • Severity - 5.6 (Medium)
GHSA-7pc3-pr3q-58vg
  • PyPI/sagemaker
sagemaker-python-sdk Command Injection vulnerability 03 May 2024
  • Fix available
  • Severity - 7.8 (High)
GHSA-wjvx-jhpj-r54r
  • PyPI/sagemaker
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data 03 May 2024
  • Fix available
  • Severity - 7.8 (High)