CVE-2026-8838

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
18/05/2026
Last modified:
18/05/2026

Description

Unsafe use of Python&amp;#39;s eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. <br /> <br /> <br /> <br /> To remediate this issue, users should upgrade to version 2.1.14.