aws / aws/aws-lambda-base-images

CVE-2026-13346 (MEDIUM): detected in Lambda Docker Images.

Open
#680 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
777
Forks
118
PR merge metrics
No merged PRs in 30d

Description

## CVE Details

| **CVE ID** | **Severity** | **Affected Package** | **Installed Version** | **Fixed Version** | **Date Published** | **Date of Scan** |
|-----------------|--------------|----------------------|-----------------------|-------------------|--------------------|------------------|
| [CVE-2026-13346](https://avd.aquasec.com/nvd/cve-2026-13346) | `MEDIUM` | `pip` | `25.0.1` | `26.2.0` | `2026-07-29T19:16:44.267Z` | `2026-09-04T10:18:40.766329584Z` |

---

## Affected Docker Images

| **Image Name** | **SHA** |
|-----------------------------|---------------------------------------|
| `public.ecr.aws/lambda/python:3.12` | `public.ecr.aws/lambda/python@sha256:68de52ae55887341b06936cd90dc55aba9a2742bc9f68b62f9608ce7b0778736` |
| `public.ecr.aws/lambda/python:3.11` | `public.ecr.aws/lambda/python@sha256:cb35f7aad530071291357b9036443d469fd85b319ef81ff5ea96593005216434` |
| `public.ecr.aws/lambda/python:3.10` | `public.ecr.aws/lambda/python@sha256:dfca83369b2194560b707c1b7f42c78c96c45aec3fba3210aa04013f1056988a` |

---

## Description

> pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels.

This vulnerability requires downloading or installing a package from a malicious package index to succeed, malicious packages alone are not able to exploit this vulnerability. Note that this vulnerability only materially impacts users running `pip download` with the `--only-binary` option as installing source distributions from an untrusted index is already an unsafe operation that executes code during install time.

---

### Remediation Steps
- Update the affected package `pip` from version `25.0.1` to `26.2.0`.

### About this issue
- This issue may not contain all the information about the CVE nor the images it affects.
- This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
- For more, visit [Lambda Watchdog](https://lambdawatchdog.com).
- This issue was created automatically by Lambda Watchdog.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.