CVE-2026-8838 - Remote Code Execution via eval() Injection in amazon-redshift-python-driver
CVE ID :CVE-2026-8838
Published : May 18, 2026, 9:16 p.m. | 5 hours, 41 minutes ago
Description :Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 18, 2026, 9:16 p.m. | 5 hours, 41 minutes ago
Description :Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...