© 2025-2026 PySpect
First version without a known vulnerability: 3.8.0
Amazon SageMaker Python SDK is missing integrity verification in its Triton inference handler
Fixed in: 2.257.2, 3.8.0
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
Fixed in: 2.257.2, 3.8.0
SageMaker Python SDK replaced eval() with safe parser in JumpStart search functionality
Fixed in: 3.4.0
SageMaker Python SDK has Exposed HMAC
Fixed in: 3.2.0, 2.256.0
SageMaker Python SDK has Insecure TLS Configuration
Fixed in: 3.1.1, 2.256.0
SageMaker Workflow component allows possibility of MD5 hash collisions
Fixed in: 2.237.3
sagemaker-python-sdk Command Injection vulnerability
Fixed in: 2.214.3
sagemaker-python-sdk vulnerable to Deserialization of Untrusted Data
Fixed in: 2.218.0