{"id":"CVE-2026-8838","aliases":["GHSA-29h4-r29x-hchv","PYSEC-2026-521"],"url":"https://o3.security/vulnerability/CVE-2026-8838","summary":"Remote Code Execution via eval() Injection in amazon-redshift-python-driver","details":"Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. \n\n\n\nTo remediate this issue, users should upgrade to version 2.1.14.","published":"2026-05-18T20:15:37.933Z","modified":"2026-08-12T03:51:48.467757195Z","cvss":null,"epss":{"score":0.00808,"percentile":0.54085,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"redshift-connector","fixedVersion":"2.1.14"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-033-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8838.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-python-driver/security/advisories/GHSA-29h4-r29x-hchv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8838"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.467757195Z"}}