sagemaker
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sagemakerpage 1 of 1
- CVE-2024-34072HIGHCVSS 7.8EG 7.8✓ Fixed in 2.218.02024-05-03
vulnerable: 1.0.0 ... 2.99.0 (580 versions)
sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted da…
- CVE-2024-34073HIGHCVSS 7.8EG 7.8✓ Fixed in 2.214.32024-05-03
vulnerable: 1.0.0 ... 2.99.0 (575 versions)
sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for p…
- CVE-2025-0508MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.237.32025-03-20
vulnerable: 1.0.0 ... 2.99.0 (614 versions)
A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from dif…
- CVE-2026-1777HIGHCVSS 7.2EG 7.2✓ Fixed in 2.256.02026-02-02
vulnerable: 1.0.0 ... 2.99.0 (650 versions)
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissi…
- CVE-2026-1778MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.256.02026-02-02
vulnerable: 1.0.0 ... 2.99.0 (650 versions)
Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed ce…
- CVE-2026-8596HIGHCVSS 7.2EG 7.2✓ Fixed in 3.8.02026-05-14
vulnerable: 3.0 ... 3.7.1 (13 versions)
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract the HMAC signing key from SageMaker API …
- CVE-2026-8597HIGHCVSS 7.2EG 7.2✓ Fixed in 3.8.02026-05-14
vulnerable: 3.0 ... 3.7.1 (13 versions)
Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code execution in inference containers via replacemen…
Check whether sagemaker is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sagemaker CVEs against the assets you own.
Start Free Scan →