MEDIUM
duckdb
CVE published 2026-08-03
CVE-2026-58139
The CVE-2026-58139 vulnerability in the DuckDB AWS extension allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false. This security policy bypass can be particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, E [truncated]