redshift-connector
Redshift Python Connector. It supports Python Database API Specification v2.0.
Activity
- Latest release
- 1mo ago
- Total releases
- 61
- Cadence
- ~28 days
- Last 12 months
- 8
Reach
- Stars
- 220
Details
- License
- Apache-2.0
- First release
- Nov 04, 2020
| Version | Released | |
|---|---|---|
2.1.16
patch
| ||
2.1.15
patch
| ||
2.1.14
patch
| ||
2.1.13
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.12
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.11
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.10
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.9
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.8
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.7
patch
1 CVE
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.6
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.5
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.4
patch
3 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-12745
PYSEC-2026-1866
GHSA-8gc2-vq6m-rwjw
Jul 07, 2026
Amazon Redshift Python Connector vulnerable to SQL Injection
Critical
Network
Low
Low
SummaryA SQL injection in the Amazon Redshift Python Connector in version 2.1.4 allows a user to gain escalated privileges via schema injection in the get_schemas, get_tables, or get_columns Metadata APIs. Users should upgrade to the driver version 2.1.5 or revert to driver version 2.1.3. ImpactA SQL injection is possible in the Amazon Redshift Python Connector, version 2.1.4, when leveraging metadata APIs to retrieve information about database schemas, tables, or columns. Impacted versions: Amazon Redshift Python Connector version 2.1.4. PatchesThe issue described above has been addressed in the Amazon Redshift Python Connector, version 2.1.5. The patch implemented in this version ensures that every metadata command input is sent to the Redshift server as part of a parameterized query, using either QUOTE_IDENT(string) or QUOTE_LITERAL(string). After processing all the inputs into quoted identifiers or literals, the metadata command is composed using these inputs and then executed on the server. WorkaroundsUse the previous version of the Amazon Redshift Python Connector, version 2.1.3. ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.1.4
Fixed in
2.1.5
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.3
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.2
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.1
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.918
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.917
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.916
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.915
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.914
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.913
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.912
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.911
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.910
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.909
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.908
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.907
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.906
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.905
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.904
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.903
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.902
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.901
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.900
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.889
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.888
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.887
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.886
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.885
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.884
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.883
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.882
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.881
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.880
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.879
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.878
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.877
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.876
patch
2 CVEs
CVE-2025-5279
PYSEC-2026-1867
GHSA-r244-wg5g-6w2r
Jul 07, 2026
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Low
Network
Low
None
None
SummaryAmazon Redshift Python Connector is a pure Python connector to Redshift (i.e., driver) that implements the Python Database API Specification 2.0. When the Amazon Redshift Python Connector is configured with the BrowserAzureOAuth2CredentialsProvider plugin, the driver skips the SSL certificate validation step for the Identity Provider. ImpactAn insecure connection could allow an actor to intercept the token exchange process and retrieve an access token. Impacted versions: >=2.0.872;<=2.1.6 PatchesUpgrade Amazon Redshift Python Connector to version 2.1.7 and ensure any forked or derivative code is patched to incorporate the new fixes. WorkaroundsNone ReferencesIf you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. [1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting Affected versions
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
+ 32 more Show less
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-8838
PYSEC-2026-521
GHSA-29h4-r29x-hchv
Jun 29, 2026
amazon-redshift-python-driver vulnerable to Remote Code Execution via eval() Injection
Critical
Network
Low
None
None
Summaryamazon-redshift-python-driver is the official Python connector for Amazon Redshift. In versions 2.1.13 and earlier, the driver insufficiently validates data received from the server during query result processing. A rogue server or man-in-the-middle could leverage this to execute arbitrary code on the client. ImpactWhen a client connects to a rogue server implementing the PostgreSQL wire protocol, the server can send specially crafted query responses that the driver processes without adequate input validation. This could result in arbitrary code execution in the client process, potentially enabling command execution, file system access, or credential theft with the privileges of the client application. Impacted versions: <=2.1.13 PatchesThis has been addressed in amazon-redshift-python-driver version 2.1.14 (https://github.com/aws/amazon-redshift-python-driver/releases/tag/v2.1.14). Amazon Redshift recommends upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ReferencesIf there are any questions or comments about this advisory, contact AWS Security via the issue reporting page or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue. AcknowledgementAmazon Redshift would like to thank Kexin Chen (@ckx-sec) for collaborating through the coordinated disclosure process. Affected versions
2.0.384
2.0.389
2.0.393
2.0.399
2.0.405
2.0.659
2.0.711
2.0.872
2.0.873
2.0.874
2.0.875
2.0.876
+ 46 more Show less
2.0.877
2.0.878
2.0.879
2.0.880
2.0.881
2.0.882
2.0.883
2.0.884
2.0.885
2.0.886
2.0.887
2.0.888
2.0.889
2.0.900
2.0.901
2.0.902
2.0.903
2.0.904
2.0.905
2.0.906
2.0.907
2.0.908
2.0.909
2.0.910
2.0.911
2.0.912
2.0.913
2.0.914
2.0.915
2.0.916
2.0.917
2.0.918
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.14
References
Updated Jul 13, 2026 · Source: OSV.dev |