Skip to content

aws-cdk-lib: bundled @aws-cdk/asset-awscli-v1@2.2.282 dependant package vulnerabilities CVE-2026-59884, CVE-2026-59885, CVE-2026-59886 #38353

Description

@twalker1998

Describe the bug

aws-cdk-lib@2.261.0 bundles @aws-cdk/asset-awscli-v1@2.2.282 which uses pyasn1@0.6.3

Security scanning is flagging this against CVE-2026-59884, CVE-2026-59885, and CVE-2026-59886.

This is patched in pyasn1@0.6.4 which is included in @aws-cdk/asset-awscli-v1@2.2.289.

Regression Issue

  • Select this option if this issue appears to be a regression.

Last Known Working CDK Library Version

No response

Expected Behavior

n/a

Current Behavior

n/a

Reproduction Steps

Install aws-cdk-lib@2.261.0 and scan dependencies

Possible Solution

No response

Additional Information/Context

No response

AWS CDK Library version (aws-cdk-lib)

2.261.0

AWS CDK CLI version

2.1118.0

Node.js Version

24

OS

MacOS

Language

TypeScript

Language Version

7.0.2

Other information

No response

Metadata

Metadata

Assignees

Labels

aws-cdk-libRelated to the aws-cdk-lib packagebugThis issue is a bug.p1

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions