AWS Security ChangesHomeSearch

AWS inspector high security documentation change

Service: inspector · 2026-01-31 · Security-related high

File: inspector/latest/user/doc-history.md

Summary

Added CVE mitigation guidance for SSM plugin/SBOM Generator, updated malicious package statistics (counts and list), and refreshed 'Latest Update' timestamp.

Security assessment

Explicitly references CVEs (CVE-2025-61728, CVE-2025-61730, etc.) and provides vulnerability mitigation guidance. Documents false positives and security resolution methods through version upgrades, constituting concrete security documentation.

Diff

diff --git a/inspector/latest/user/doc-history.md b/inspector/latest/user/doc-history.md
index 069dd0a5a..9ed495491 100644
--- a//inspector/latest/user/doc-history.md
+++ b//inspector/latest/user/doc-history.md
@@ -14,0 +15 @@ Change| Description| Date
+[Updates for the Amazon Inspector SSM plugin and Amazon Inspector SBOM Generator](./doc-history.html)|  Amazon Inspector is aware of a scenario where the Amazon Inspector SSM plugin and Amazon Inspector SBOM Generator may generate vulnerability findings for `CVE-2025-61728, CVE-2025-61730, and CVE-2025-61726`. These vulnerabilities can be resolved by upgrading the Amazon Inspector SSM plugin version to 1.0.2327.0, or Amazon Inspector SBOM Generator 1.10.1 or later. | January 29, 2026  
@@ -16,0 +18 @@ Change| Description| Date
+[Updates for Amazon Inspector SBOM Generator](./doc-history.html)|  Amazon Inspector is aware of a scenario where the Amazon Inspector SBOM Generator might generate vulnerability findings for `CVE-2025-47914` and `CVE-2025-58181`. It was confirmed the Amazon Inspector SBOM Generator is not impacted by these CVEs. We are presently working on improvements to resolve these detections. In the mean time, customers may safely ignore or suppress these vulnerabilities. | November 20, 2025  
@@ -103 +105 @@ Amazon Inspector continuously monitors and identifies malicious packages from th
-**Latest Update:** 2026-01-16 12:00:00 UTC 
+**Latest Update:** 2026-01-23 12:00:00 UTC 
@@ -107 +109 @@ Amazon Inspector continuously monitors and identifies malicious packages from th
-  * **Lifetime Total:** 191,402 malicious packages identified
+  * **Lifetime Total:** 191,545 malicious packages identified
@@ -109 +111 @@ Amazon Inspector continuously monitors and identifies malicious packages from th
-  * **This Month:** 275 new malicious packages identified
+  * **This Month:** 418 new malicious packages identified
@@ -113 +115 @@ Amazon Inspector continuously monitors and identifies malicious packages from th
-  * **This Week:** 110 new malicious packages identified
+  * **This Week:** 138 new malicious packages identified
@@ -115 +117 @@ Amazon Inspector continuously monitors and identifies malicious packages from th
-  * **Last Week:** 142 new malicious packages identified
+  * **Last Week:** 115 new malicious packages identified
@@ -124,10 +126,10 @@ Package Name | MAL-ID | Detection Date
-sparkling-router | MAL-2026-311 | 2026-01-15  
-spire.officejs-externs | MAL-2026-312 | 2026-01-15  
-spire.officejs-fonts | MAL-2026-313 | 2026-01-15  
-styled-system-old | MAL-2026-314 | 2026-01-15  
-tailwind-merge-v2 | MAL-2026-315 | 2026-01-15  
-tailwind-merge-v3 | MAL-2026-316 | 2026-01-15  
-textual-sorter-lib | MAL-2026-317 | 2026-01-15  
-victim-package-a | MAL-2026-318 | 2026-01-15  
-vue_frontend_rpc | MAL-2026-319 | 2026-01-15  
-zis-common-lib | MAL-2026-320 | 2026-01-15  
+@transaction-list/transaction-list-sm | MAL-2026-475 | 2026-01-22  
+@transaction-list/transaction-list-xs | MAL-2026-476 | 2026-01-22  
+bttr-devs | MAL-2026-477 | 2026-01-22  
+domino-elements | MAL-2026-478 | 2026-01-22  
+integromat-ui | MAL-2026-479 | 2026-01-22  
+kwp-shared-components-production-system | MAL-2026-480 | 2026-01-22  
+oasis-os-provider-messaging | MAL-2026-481 | 2026-01-22  
+public-site-boostmoney-ui | MAL-2026-482 | 2026-01-22  
+public-site-cms-ui | MAL-2026-483 | 2026-01-22  
+translation-note | MAL-2026-484 | 2026-01-22