GHSA-rq6v-x3j8-7qgf · Severity: medium · Ecosystem: pip — Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code execution in inference containers via replacement of model artifacts in S3 with a specially crafted pickle payload that is deserialized without verification. This issue requires a remote authenticated actor with S3 write access to the model artifact path. To remediate this issue, we recommend upgrading to Amazon SageMaker Python SDK v2.257.2 or v3.8.0 and rebuild any Triton models previously created with ModelBuilder using the updated SDK.
Conclusion & alert: CVE-2026-8597 is rated Low Risk (30.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.04%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.10% | 0.04% | -0.05% |
| 2 | 2026-05-15 | — | 0.10% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.4 | 4.0 | MEDIUM |
|
— | — | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
| 7.2 | 3.1 | HIGH |
|
1.2 | 5.9 | ff89ba41-3aa1-4d27-914a-91399e9639e5 |
GHSA-rq6v-x3j8-7qgf · Severity: medium · Ecosystem: pip — Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||