← العودة للجدول
CVE-2026-8838
CVE-2026-8838 — GHSA: amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
📅 2026-05-29
🔴 Critical 🔥 No GHSA Exploit Exploit CVSS 9.8 🎯 EPSS 0.08%

📋 الوصف الكامل

### Summary amazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ### Impact When a client connects to a rogue server implementing the Postgre

💻 الأنظمة المتأثرة

GHSA: amazon-redshift-python-driver vulnerable

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-8838

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←