Description
Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.
Problem types
CWE-502 Deserialization of untrusted data
Product status
1.10.0 (custom) before 1.117.0
References
github.com/...amazon-braket-sdk-python/releases/tag/v1.117.0
aws.amazon.com/security/security-bulletins/2026-036-aws/
github.com/...python/security/advisories/GHSA-g697-2xrc-gc46