CVE-2026-8838
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
- Affected products
- Amazon-Redshift-Python-Driver
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-94
- NVD status
- Awaiting Analysis
- Published
- 2026-05-18
- Attack patterns
- CAPEC-242
CVE-2026-8838 at NVD
3 known exploits for CVE-2026-8838
Proof-of-concept code and exploit modules indexed by Sploitus