
CVE-2026-1777 The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob func… https://www.cve.org/CVERecord?id=CVE-2026-1777
Post summary
The Amazon SageMaker Python SDK releases before v3.2.0 and v2.256.0 expose the ModelBuilder HMAC signing key in cleartext within the DescribeTrainingJob response, constituting an information‑disclosure vulnerability.


