Summary
Bulletin ID: 2026-131-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 12:30 PM PDT
Description:
AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation.
We identified CVE-2026-107608, which is an issue where Docker files could be configured to insert symlinked files into the output of the AWS CDK asset bundling process when it was invoked with a Docker file.
When bundling an asset using AWS CDK with a docker file, prior to 2.267.0, it was possible for a docker file to insert a symlinked file or directory into the output of asset bundling without the symlink having been provided as input to the bundling process.
Impacted versions: All aws-cdk-lib versions before 2.267.0
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
Separate remediation guidance was not included in the collected bulletin.
CVEs in this advisory 1
Updates
- Published by AWS
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.