Amazon SageMaker Python SDK Insecure TLS Configuration Vulnerability

Vulnerability

A vulnerability exists in the Amazon SageMaker Python SDK in versions prior to 3.1.1 and 2.256.0, where TLS certificate verification is disabled for HTTPS connections made by the service when a Triton Python model is imported. This flaw allows requests with invalid or self-signed certificates to be accepted. The issue was introduced to bypass SSL errors during model downloads from public sources, such as TorchVision, and affects all HTTPS connections when the Triton Python model is used.

Impact

Exploitation of this vulnerability allows for the acceptance of invalid and self-signed TLS certificates, potentially leading to man-in-the-middle attacks or the interception of sensitive data.

Remediation

Users are advised to upgrade to Amazon SageMaker Python SDK versions 3.1.1 or 2.256.0. For those using self-signed certificates for internal model downloads, add the private Certificate Authority (CA) certificate to the container image instead of relying on the SDK's previous insecure configuration.

Added: Feb 2, 2026, 11:38 PM
Updated: Feb 2, 2026, 11:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.8
remediation
0.0
relevance
2.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.