Summary
Bulletin ID: 2026-133-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/09/2026 11:00 AM PDT
Description:
AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.
Impacted versions:
- @aws-amplify/graphql-index-transformer >=2.2.0, <3.1.2;
- @aws-amplify/graphql-api-construct >=1.4.0, <1.21.4;
- @aws-amplify/data-construct <1.17.4
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Products covered
A separate affected-products list was not included in the collected bulletin.
Remediation
Separate remediation guidance was not included in the collected bulletin.
CVEs in this advisory 1
Updates
- Published by AWS
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.
- Confirmed at the source
Our collector saw this advisory during a later source check.