CVE-2026-8838
Severity CVSS v4.0:
CRITICAL
Type:
CWE-94
Code Injection
Publication date:
18/05/2026
Last modified:
18/05/2026
Description
Unsafe use of Python&#39;s eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. <br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to version 2.1.14.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
9.80
Severity 3.x
CRITICAL



