Unrated severityNVD Advisory· Published May 22, 2026· Updated May 22, 2026
Insecure Deserialization in Amazon Braket SDK Job Results Processing
CVE-2026-9291
Description
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.
We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.
Affected products
1- Range: <1.117.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/amazon-braket/amazon-braket-sdk-python/releases/tag/v1.117.0mitrepatch
- aws.amazon.com/security/security-bulletins/2026-036-aws/mitrevendor-advisory
- github.com/amazon-braket/amazon-braket-sdk-python/security/advisories/GHSA-g697-2xrc-gc46mitrethird-party-advisory
News mentions
0No linked articles in our index yet.