VYPR

aws-iot-device-sdk-python

by AWS

CVEs (1)

  • CVE-2026-92943HigSep 17, 2026
    risk 0.53cvss 8.1epss

    Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device…