CVE-2026-8838
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client.
To remediate this issue, users should upgrade to version 2.1.14.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://aws.amazon.com/security/security-bulletins/2026-033-aws/, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8838.json, https://github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-29h4-r29x-hchv, https://nvd.nist.gov/vuln/detail/CVE-2026-8838, https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14