Skip to content

Prowler

v5.33.2 Bugfix

This release fixes issues for SREs watching stability and regressions.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’

✓ No known CVEs patched in this version

Topics

aws azure cis-benchmark cloud cloudsecurity compliance
+12 more
cspm security forensics gcp gdpr hardening iam multi-cloud python security-audit security-hardening security-tools

Summary

AI summary

Updates 🐞 Fixed, API, and https://github.com/prowler-cloud/prowler/pull/11968 across a mixed release.

Changes in this release

Bugfix Medium

Attack Paths graph mutations now retry transient Neptune concurrency and deadline failures, while Neo4j mutations use managed transaction retries

Attack Paths graph mutations now retry transient Neptune concurrency and deadline failures, while Neo4j mutations use managed transaction retries

Source: llm_adapter@2026-07-14

Confidence: high

β€”
Bugfix Medium

Attack Paths scans now use bounded child node identifiers for normalized list values in Neo4j and Neptune, preventing Neo4j RANGE index key size failures

Attack Paths scans now use bounded child node identifiers for normalized list values in Neo4j and Neptune, preventing Neo4j RANGE index key size failures

Source: llm_adapter@2026-07-14

Confidence: high

β€”
Bugfix Medium

`scan-summary` aggregation now upserts summaries in deterministic conflict-key order, preventing PostgreSQL deadlocks during concurrent reaggregation

`scan-summary` aggregation now upserts summaries in deterministic conflict-key order, preventing PostgreSQL deadlocks during concurrent reaggregation

Source: llm_adapter@2026-07-14

Confidence: high

β€”
Bugfix Medium

EC2 AMI loading now targets Amazon-owned AMIs used by audited instances, reducing AWS API calls during EC2 scans

EC2 AMI loading now targets Amazon-owned AMIs used by audited instances, reducing AWS API calls during EC2 scans

Source: llm_adapter@2026-07-14

Confidence: high

β€”
Bugfix Medium

'ec2_instance_account_imdsv2_enabled' findings now use regional resource ARNs, preventing cross‑region finding collapse

'ec2_instance_account_imdsv2_enabled' findings now use regional resource ARNs, preventing cross‑region finding collapse

Source: llm_adapter@2026-07-14

Confidence: high

β€”
Full changelog

API

🐞 Fixed

  • Attack Paths graph mutations now retry transient Neptune concurrency and deadline failures, while Neo4j mutations use managed transaction retries (#11968)
  • Attack Paths scans now use bounded child node identifiers for normalized list values in Neo4j and Neptune, preventing Neo4j RANGE index key size failures (#11969)
  • scan-summary aggregation now upserts summaries in deterministic conflict-key order, preventing PostgreSQL deadlocks during concurrent reaggregation (#11971)

SDK

🐞 Fixed

  • EC2 AMI loading now targets Amazon-owned AMIs used by audited instances, reducing AWS API calls during EC2 scans (#11958)
  • ec2_instance_account_imdsv2_enabled findings now use regional resource ARNs, preventing findings from different AWS Regions from collapsing into one resource (#11966)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Prowler

Get notified when new releases ship.

Sign up free

About Prowler

Tool based on AWS-CLI commands for Amazon Web Services account security assessment and hardening.

All releases β†’

Related context

Earlier breaking changes

  • v5.34.0 Renames UI integration enable flags to past tense (e.g., UI_SENTRY_ENABLE β†’ UI_SENTRY_ENABLED).

Beta — feedback welcome: [email protected]