AWS Security ChangesHomeSearch

AWS inspector medium security documentation change

Service: inspector · 2026-06-04 · Security-related medium

File: inspector/latest/user/doc-history.md

Summary

Added entry about false positive vulnerability findings for CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507 affecting Amazon Inspector tools, confirming they're not vulnerable and will be resolved in next release

Security assessment

Explicitly references specific CVEs and confirms tools are not vulnerable, addressing potential false positive security findings. This directly documents security-related behavior of the tools.

Diff

diff --git a/inspector/latest/user/doc-history.md b/inspector/latest/user/doc-history.md
index 487fb07f0..c31a87bc6 100644
--- a//inspector/latest/user/doc-history.md
+++ b//inspector/latest/user/doc-history.md
@@ -17 +17,2 @@ Change| Description| Date
-[New feature](./doc-history.html)|  To perform enhanced vulnerability assessments of Amazon Elastic Compute Cloud instances, you can now use the Amazon Inspector VM Scanner instead of the Amazon Inspector SSM plugin. The Inspector VM Scanner provides several advantages, such as more granular package collection, and it uses fewer compute resources. For more information, see [Amazon Inspector VM Scanner](https://docs.aws.amazon.com/inspector/latest/user/inspector-vm-scanner.html). | May 29, 2026  
+[Updates for the Amazon Inspector SSM plugin, Amazon Inspector SBOM Generator, and Amazon Inspector VM Scanner](./doc-history.html)|  Amazon Inspector is aware of a scenario where the Amazon Inspector SSM plugin, Amazon Inspector SBOM Generator, and Amazon Inspector VM Scanner may generate vulnerability findings for CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507. It was confirmed that the Amazon Inspector SSM plugin, Amazon Inspector SBOM Generator, and Amazon Inspector VM Scanner are not impacted by these vulnerabilities. These findings will be resolved in the next release of the Amazon Inspector SSM plugin, Amazon Inspector SBOM Generator, and Amazon Inspector VM Scanner. | June 3, 2026  
+[New feature](./doc-history.html)|  To perform enhanced vulnerability assessments of Amazon Elastic Compute Cloud instances, you can now use the Amazon Inspector VM Scanner instead of the Amazon Inspector SSM plugin. The Amazon Inspector VM Scanner provides several advantages, such as more granular package collection, and it uses fewer compute resources. For more information, see [Amazon Inspector VM Scanner](https://docs.aws.amazon.com/inspector/latest/user/inspector-vm-scanner.html). | May 29, 2026