Back to vendor advisories
AWS Security BulletinsCVE-2026-107608

CVE-2026-107608: Improper link resolution in asset bundling output handling in aws-cdk-lib

Severity not listed 1 CVE Published Oct 8, 2026 at 7:44 PM UTC

Summary

Bulletin ID: 2026-131-AWS

Scope: AWS

Content Type: Important (requires attention)

Publication Date: 10/08/2026 12:30 PM PDT

Description:

AWS CDK is an open source framework that allows customers to build cloud infrastructure using their favorite programming language (Python, Typescript, C#, Go). That infrastructure is then able to be deployed with AWS CDK command line commands to AWS CloudFormation.

We identified CVE-2026-107608, which is an issue where Docker files could be configured to insert symlinked files into the output of the AWS CDK asset bundling process when it was invoked with a Docker file.

When bundling an asset using AWS CDK with a docker file, prior to 2.267.0, it was possible for a docker file to insert a symlinked file or directory into the output of asset bundling without the symlink having been provided as input to the bundling process.

Impacted versions: All aws-cdk-lib versions before 2.267.0

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Products covered

A separate affected-products list was not included in the collected bulletin.

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by AWS

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.