Bedrock, LangSmith, SGLang expose DNS, token, RCE

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Amazon Bedrock' sandbox‑mode Code Interpreter permits outbound DNS queries, enabling interactive shells and bypassing network isolation (CVSS 7.5, no CVE ID).
- Amazon advises customers to migrate critical workloads from sandbox to VPC mode and to use DNS firewalls to block unauthorized DNS resolution.
- LangSmith had a high‑severity URL‑parameter injection flaw (CVE‑2026‑25750, CVSS 8.5) that let attackers steal bearer tokens and take over accounts via crafted baseUrl links.
- LangSmith fixed the vulnerability in version 0.12.71 released in December 2025, covering both cloud and self‑hosted deployments.
- SGLang contains three unsafe pickle‑deserialization bugs (CVE‑2026‑3059, CVE‑2026‑3060, CVE‑2026‑3989) that permit unauthenticated remote code execution through its ZeroMQ broker and disaggregation modules.
- CERT/CC warns that exposing SGLang’s multimodal generation or disaggregation interfaces to untrusted networks can be exploited, and recommends network segmentation and access controls.
Why it matters: Attackers can bypass sandbox isolation on Amazon Bedrock, steal data via DNS, hijack LangSmith accounts by stealing tokens, and remotely execute code on SGLang servers, exposing sensitive customer information and causing service disruption for users of these AI platforms across multiple industries.




