CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

Published 2026-08-20T21:35:57Zbd2d052cdc5dd51ff34aa0e9a67ffced0a39dba4d77fb5b859376b9590a2e6f6

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
9192d6ceab487cb79480c97c8eed74e1b3d36cf5
Public record ID
record:sha256:bd2d052cdc5dd51ff34aa0e9a67ffced0a39dba4d77fb5b859376b9590a2e6f6

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
bd2d052cdc5dd51ff34aa0e9a67ffced0a39dba4d77fb5b859376b9590a2e6f6
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() · Baitaphish