VYPR

PyPI package

sagemaker

pkg:pypi/sagemaker

Vulnerabilities (5)

  • CVE-2026-1778MedFeb 2, 2026
    affected >= 3.0, < 3.1.1fixed 3.1.1

    Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed.

  • CVE-2026-1777HigFeb 2, 2026
    affected >= 3.0, < 3.2.0fixed 3.2.0

    The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Job

  • CVE-2025-0508MedMar 20, 2025
    affected < 2.237.3fixed 2.237.3

    A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the sa

  • CVE-2024-34073HigMay 3, 2024
    affected < 2.214.3fixed 2.214.3

    sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected versions the capture_dependencies function in `sagemaker.serve.save_retrive.version_1_0_0.save.utils` module allows for potentially unsafe Operating System (OS) C

  • CVE-2024-34072HigMay 3, 2024
    affected < 2.218.0fixed 2.218.0

    sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. The sagemaker.base_deserializers.NumpyDeserializer module before v2.218.0 allows potentially unsafe deserialization when untrusted data is passed as pickled object arrays. Th