S2n Tls Amazon S2n Tls

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazon S2n Tls.

By the Year

In 2026 there have been 1 vulnerability in Amazon S2n Tls with an average score of 5.3 out of ten.

Year Vulnerabilities Average Score
2026 1 5.30

It may take a day or so for new S2n Tls vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon S2n Tls Security Vulnerabilities

s2n-tls <1.7.6 QUIC HRS memory leak via s2n_alloc
CVE-2026-16318 5.3 - Medium - July 21, 2026

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes the existing pointer before allocating new memory, causing the first allocation to be leaked. This can occur during normal QUIC traffic when a client offers a key share group the server does not prefer. An unauthenticated user can amplify the issue by deliberately forcing HelloRetryRequests, causing up to approximately 64 KB of unreachable memory per handshake. Over time, this can lead to increased memory consumption on long-running server processes. The unreachable memory is only reclaimed when the process is restarted. Only server-side QUIC-enabled deployments are affected. Non-QUIC TLS connections are not affected. We recommend you upgrade s2n-tls to version v1.7.6

Memory Leak

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazon S2n Tls or by Amazon? Click the Watch button to subscribe.

Amazon
Vendor

subscribe