Back

HIGH

Insecure Deserialization in Amazon Braket SDK Job Results Processing

Published May 22, 2026

Description

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results.

We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.

Affected products

Remediation

No remediation recorded yet.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner AMZN
Published May 22, 2026
Updated May 22, 2026
Reserved May 22, 2026

CISA Vulnrichment

Updated May 22, 2026

NVD

Status Awaiting Analysis
Modified Jul 23, 2026

Red Hat

No data

ENISA EUVD

Assigner AMZN
Published May 22, 2026
Updated May 22, 2026