CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
Cybersecurity Classified by Officially
CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
Bulletin ID: 2026-114-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/17/2026 12:00 PM PDT
AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-middle positioned on the network could present a certificate issued for an unrelated hostname by any certificate authority in the device trust store, impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic. Both SDK default connection paths were affected: X.509 mutual authentication on port 8883 and WebSocket with SigV4 on port 443. The port 443 ALPN path was not affected.
Impacted versions: >=1.5.3 AND <=1.6.0 (on Python 3.7 and later)
This issue has been addressed in AWSIoTPythonSDK version 1.6.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
There is no workaround. The affected connection paths are the SDK's documented defaults. Customers must upgrade to version 1.6.1.
We would like to thank George Chen for collaborating on this issue through the coordinated vulnerability disclosure process.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-114-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 17, 2026 19:30
- Versions
- 2 recorded
- Identity
3adafdffd77ca34d47e6af3baa2e350cb330cfd0