CVE-2026-8838: amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
(updated )
amazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client.
References
- aws.amazon.com/security/security-bulletins/2026-033-aws
- github.com/advisories/GHSA-29h4-r29x-hchv
- github.com/aws/amazon-redshift-python-driver/commit/69a69dfdead75918e20384da52bcd760ded8dbca
- github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14
- github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-29h4-r29x-hchv
- nvd.nist.gov/vuln/detail/CVE-2026-8838
Code Behaviors & Features
Detect and mitigate CVE-2026-8838 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →