CVE coverage
View on NVD →
CVE-2026-107608
CVSS 5.5
no coverage
Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset.
To remediate this issue, users should upgrade to version 2.267.0 or later.
Detection rules
No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2026-107608.