PyPI: sagemaker
CVE-2026-1777
Safety vulnerability ID: SFTY-20260202-33918
Safety legacy ID: pyup.io-85692
Affected versions of the sagemaker package are vulnerable to Information Disclosure due to an HMAC secret key being stored in environment variables that are disclosed via the SageMaker DescribeTrainingJob API. The SageMaker Python SDK places the remote-function HMAC signing key into the training job environment, and the DescribeTrainingJob response exposes that value, allowing an attacker to bypass the intended integrity check for serialized remote function payloads stored in S3.
Overview
SageMaker Python SDK has Exposed HMAC
Advisory
Affected versions of the sagemaker package are vulnerable to Information Disclosure due to an HMAC secret key being stored in environment variables that are disclosed via the SageMaker DescribeTrainingJob API. The SageMaker Python SDK places the remote-function HMAC signing key into the training job environment, and the DescribeTrainingJob response exposes that value, allowing an attacker to bypass the intended integrity check for serialized remote function payloads stored in S3.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260202-33918/CVE-2026-1777
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-1777
- https://github.com/advisories/GHSA-rjrp-m2jw-pv9c
- https://github.com/aws/sagemaker-python-sdk/commit/708c7b2f4135ecaec55973d098f3dbe98b657933
- https://github.com/aws/sagemaker-python-sdk/commit/fb0d789db4fd5fecde5509963939369f4c7ce63b
- https://github.com/aws/sagemaker-python-sdk/security/advisories/GHSA-rjrp-m2jw-pv9c
- https://github.com/aws/sagemaker-python-sdk/commit/708c7b2f4135ecaec55973d098f3dbe98b657933
- https://github.com/aws/sagemaker-python-sdk/commit/fb0d789db4fd5fecde5509963939369f4c7ce63b
- https://nvd.nist.gov/vuln/detail/CVE-2026-1777
- https://aws.amazon.com/security/security-bulletins/2026-004-AWS
- https://github.com/aws/sagemaker-python-sdk/releases/tag/v2.256.0
- https://github.com/aws/sagemaker-python-sdk/releases/tag/v3.2.0
- https://github.com/advisories/GHSA-rjrp-m2jw-pv9c
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
