Aws Aws

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Aws product.

RSS Feeds for Aws security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Aws products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Aws Sorted by Most Security Vulnerabilities since 2018

Aws Strands Agents Tools3 vulnerabilities

Aws Ops Wheel3 vulnerabilities

Aws Opensearch3 vulnerabilities

Aws Kiro Ide2 vulnerabilities

Aws Sdk Cpp2 vulnerabilities

Aws Bedrock Agentcore2 vulnerabilities

Aws Advanced Jdbc Wrapper2 vulnerabilities

Qnabot On Aws1 vulnerability

Rabbitmq Aws1 vulnerability

Aws Mcp Gateway Registry1 vulnerability

Aws Sdk Rust1 vulnerability

Aws Kiro Cli1 vulnerability

Aws Jsii1 vulnerability

Aws Graph Explorer1 vulnerability

Aws Documentdb Mcp Server1 vulnerability

Aws Res1 vulnerability

Aws S2n Quic1 vulnerability

Aws S2n Tls1 vulnerability

Aws Transform Mcp Server1 vulnerability

Aws Api Mcp Server1 vulnerability

Aws Amazon Ecs Agent1 vulnerability

Aws Amazon Mq Mcp Server1 vulnerability

Aws Amplify Codegen Ui1 vulnerability

Aws Advanced Go Wrapper1 vulnerability

Aws Smithy Json1 vulnerability

Aws C Http1 vulnerability

Aws Cdk1 vulnerability

Aws Cli1 vulnerability

Aws Agentcore Cli1 vulnerability

Aws Smithy Http Server1 vulnerability

By the Year

In 2026 there have been 59 vulnerabilities in Aws with an average score of 7.5 out of ten.

Year Vulnerabilities Average Score
2026 59 7.49

It may take a day or so for new Aws vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aws Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-18420 Aug 20, 2026
OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution) Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Amazon Opensearch Service
CVE-2026-75910 Aug 20, 2026
Amazon Athena Query ClickHouse Connector v2026.17.1 Priv Escalation Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.
Athena Federated Query Clickhouse Connector Deployment Template
CVE-2026-75897 Aug 18, 2026
OpenSearch Dashboards Capabilities Route Unbounded Payload DOS Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
Amazon Opensearch Service
CVE-2026-18428 Aug 13, 2026
OpenSearch SQL Plugin Flint SQL Bypass Allows Arbitrary Code Execution on Spark A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.
Opensearch
CVE-2026-19643 Aug 12, 2026
aws-sdk-c++ OOB Read: Base64 Decoder <1.11.862 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Aws Sdk Cpp
CVE-2026-19642 Aug 12, 2026
OOB Write in aws-sdk-cpp Base64 Decoder before 1.11.862 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Aws Sdk Cpp
CVE-2026-18952 Aug 12, 2026
OpenSearch SecurityAnalytics Plugin SSRF via Unvalidated Threat Intel Feed URL Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.
Opensearch
CVE-2026-19311 Aug 12, 2026
Missing Auth in OpenSearch Execute Monitor API Enables Data Manipulation Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.
Opensearch
CVE-2026-19111 Aug 06, 2026
Insecure DOOR in Amazon Strands Agent Tools <0.8.3 (memory tools) Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace parameter. To remediate this issue, users should upgrade to version 0.8.3.
Strands Agents Tools
CVE-2026-18954 Aug 05, 2026
Amazon AWS Labs DocumentDB MCP Server 1.0.11 Aggregation Pipeline Auth Bypass Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP client to perform inappropriate write operations on the connected database via write-capable aggregation pipeline stages that bypass the read-only mode enforcement logic. To remediate this issue, users should upgrade to version 1.0.12 or later.
Documentdb Mcp Server
CVE-2026-18953 Aug 05, 2026
Amazon awslabs.aws-transform-mcp-server 0.1.0-0.1.4 Pathname Traversal via savePath Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 might allow a context-dependent actor to write arbitrary files outside the intended working directory via the savePath parameter. To remediate this issue, users should upgrade to version 0.1.5 or later.
Aws Transform Mcp Server
CVE-2026-18830 Aug 04, 2026
Bedrock AgentCore Flaw Lets Authenticated Remote Users Execute Tools Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required.
Amazon Bedrock Agentcore Harness
CVE-2026-18733 Aug 03, 2026
Prompt Injection in Amazon Strands Agents Tools <0.8.0 Allows Remote OS Cmd Exec A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue, users should upgrade to version 0.8.0.
Strands Agents Tools
CVE-2026-18654 Aug 03, 2026
MITM in AWS CLI v1/<1.45.28 & v2/<2.35.3: EMR SSH Helper key exchange w/o auth Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR cluster endpoint. To remediate this issue, users should upgrade to AWS CLI v1 1.45.28 or later, or AWS CLI v2 2.35.3 or later.
Aws Cli
CVE-2026-18655 Aug 03, 2026
Amazon MQ MCP Server RabbitMQ Connector Endpoint Bypass <=2.0.24 Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or OAuth access tokens sent to a crafted endpoint controlled through a broker hostname introduced in the MCP client context. To remediate this issue, users should upgrade to version 2.0.24.
Amazon Mq Mcp Server
CVE-2026-18394 Jul 31, 2026
Strands Agents Tools 0.8.2: http_request tool Insecure Authorization Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.
Strands Agents Tools
CVE-2026-18481 Jul 31, 2026
Stored XSS in AWS Ops Wheel participant_url handling Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
Aws Ops Wheel
CVE-2026-18140 Jul 30, 2026
aws-smithy-json <=0.62.6 Recursion DoS via JSON payload Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild.
Aws Smithy Json
CVE-2026-18245 Jul 30, 2026
Amplify Codegen UI React <2.20.6: Remote Code Exec via Studio Schema Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318. To remediate this issue, users should upgrade to version 2.20.6
Amplify Codegen Ui
CVE-2026-16796 Jul 23, 2026
Amazon Bedrock AgentCore SDK <1.18.1: install_packages() allows code exec Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1.
Bedrock Agentcore 1 18 1
CVE-2026-16756 Jul 23, 2026
Denial of Service via Missing Timeouts in aws-smithy-http-server <=0.66.4 Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-server 0.66.5 or later.
Aws Smithy Http Server
CVE-2026-16584 Jul 23, 2026
AWS API MCP Server 0.2.13-1.3.46 Init Failure Bypass Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on the configured credentials remain in effect and are unaffected. To remediate this issue, users should upgrade to version 1.3.47.
Aws Api Mcp Server
CVE-2026-16317 Jul 21, 2026
s2n-tls before 1.7.6: TLS1.3 Content Type bypass MITM Silent Record Drop Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. RFC 8446 Section 5.2 requires that the outer content_type of all encrypted TLS 1.3 records must be application_data (0x17). The s2n-tls AEAD implementation hardcodes this value in the additional authenticated data rather than using the actual wire byte, so the outer content_type is not covered by the authentication tag. This enables selective suppression of application data. In HTTP pipelining scenarios, dropping a TLS record containing an HTTP request can cause request/response desynchronization, where subsequent responses are delivered to the wrong requests. In write-heavy workloads, a dropped record containing a write request can result in undetectable data loss when the client interprets a subsequent success response as confirmation of the dropped write. All TLS 1.3 connections are affected. Both TLS clients and servers are affected. TLS 1.2 and QUIC connections are not affected. We recommend you upgrade s2n-tls to version v1.7.6
S2n Tls
CVE-2026-15957 Jul 21, 2026
SmithyRS Recursive Deserializer Causing DoS Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow remote attackers to cause a denial of service (process abort via stack exhaustion) via a small request containing deeply nested data for a recursive model shape to a generated SDK or server. To mitigate this issue, users should upgrade to aws-sdk-rust release-2026-06-02 or later. Users building custom servers with smithy-rs codegen should regenerate from smithy-rs release-2026-06-01 or later.
Aws Sdk Rust
CVE-2026-15415 Jul 17, 2026
Directory Traversal in aws-healthomics-mcp-server linting (v<0.0.36) AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools of the AWS HealthOmics MCP Server (aws-healthomics-mcp-server) before version 0.0.36 might allow an actor who can influence the MCP agent to write an actor-controlled content to arbitrary locations outside the intended workflow bundle directory, via directory traversal sequences in the workflow_files input. To remediate this issue, users should upgrade to version 0.0.36 or later.
Aws Healthomics Mcp Server
CVE-2026-12283 Jul 17, 2026
AWS Athena Federation Synapse SQL Injection (Prev2026.21.1) Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. Improper neutralization of special elements used in an SQL command in the Synapse connector in Amazon aws-athena-query-federation v2022.20.1 through v2026.19.1 might allow an authenticated remote user to execute injected read-only SQL queries that return unintended data from the connected database via a crafted table name. To remediate this issue, users should upgrade to version v2026.21.1 or later.
Aws Athena Query Federation
CVE-2026-15737 Jul 16, 2026
AWS Bedrock AgentCore SDK 1.4.8/1.5.0 Logleaks via OT Span Attrs AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a local authenticated user with access to CloudWatch Logs to access raw user prompts and agent responses containing sensitive data via span attributes. The SDK wrote raw user prompts and complete agent responses into OpenTelemetry span attributes on every invocation without filtering or masking. These spans flow into the customer's aws/spans CloudWatch log group, exposing sensitive content to any principal with log read access. We recommend you upgrade to version 1.5.1 or later. Users who ran affected versions should also review and purge sensitive content from their aws/spans CloudWatch log groups.
Bedrock Agentcore
CVE-2026-15895 Jul 15, 2026
OS Command Injection in AWS jsii-diff (v<1.131.0) npm loading component OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent attackers to execute arbitrary commands via crafted package specifiers passed to the npm: source argument. To mitigate this issue, users should upgrade to jsii-diff v1.131.0 or later.
Jsii
CVE-2026-15643 Jul 14, 2026
AWS HealthLake MCP Server SSRF: Pagination Handling before v0.0.14 AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a remote authenticated user to exfiltrate AWS temporary security credentials to an arbitrary endpoint via a crafted next_token parameter. The server does not validate that pagination URLs point back to the expected HealthLake endpoint, allowing an actor to redirect subsequent requests to an actor-controlled server. Its recommended to upgrade to version 0.0.14 or later.
Awslabs Healthlake Mcp Server
CVE-2026-14904 Jul 07, 2026
Auth.GetUserPrivateKey API CWE-59 in AWS RES <2026.06: Improper Link Res AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file (~/.ssh/id_rsa) with a symbolic link targeting any file on the host. Because the cluster-manager process runs as root, any file readable by root is exposed, including other users' SSH private keys and application configuration secrets. It's recommended to upgrade to RES version 2026.06.
Res
CVE-2026-14471 Jul 06, 2026
Amazon mcp-gateway-registry <1.0.13 SQLi via retention policy Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. To remediate this issue, users should upgrade to version 1.0.13 or later.
Mcp Gateway Registry
CVE-2026-14265 Jul 01, 2026
AWS Advanced JDBC Wrapper 3.3-4.0 RemoteQueryCachePlugin Deserialization RCE Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned. We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later.
Aws Advanced Jdbc Wrapper
CVE-2026-13760 Jul 01, 2026
OS Command Injection in aws-cdk-lib NodejsFunction Docker Bundling (v2.260.0 Fix) OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who controls dependency version strings in a project's package.json file to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters in the OsCommand helper. This issue requires the actor to control the content of a package.json dependency version string that is processed during Docker-based bundling with nodeModules specified. To remediate this issue, users should upgrade to v2.260.0.
Aws Cdk
CVE-2026-13769 Jul 01, 2026
AWS CLI <=1.44.77 / <=2.34.28: Overly Permissive File Permissions Expose Credentials Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict file permissions (the default on most systems) may allow other local users on the same host to read credentials written by certain CLI subcommands (aws codeartifact login, aws iam create-virtual-mfa-device, aws deploy register). To remediate this issue, users should upgrade to AWS CLI 1.44.78 (v1) or 2.34.29 (v2) or later.
CVE-2026-13763 Jun 29, 2026
AWS ALB HTTP/2 WAF Bypass via Fragmented Body Inspection Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )
CVE-2026-13762 Jun 29, 2026
CloudFront AWS WAF HTTP/2 Body Inspection Bypass Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.
CVE-2026-12530 Jun 17, 2026
AWS Bedrock AgentCore SDK 1.1.3-1.6.1 Remote Cmd via install_packages Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to version 1.6.1.
Bedrock Agentcore
CVE-2026-11931 Jun 15, 2026
Kiro IDE 0.11.133 fixes insecure token cache permissions (CVE-2026-11931) Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or processes via world-readable permissions (0644) instead of owner-restricted permissions (0600). To remediate this issue, users should upgrade to Kiro IDE version 0.11.133 or later. After upgrading and restarting the application, the cache file permissions are automatically updated on the next token refresh. Users operating in a multi-user environment can invalidate existing tokens by reauthenticating.
Kiro Ide
CVE-2026-12043 Jun 12, 2026
AWS Common Runtime aws-c-http 0.11.0: HPACK CVE-2026-12043 Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
Aws C Http
CVE-2026-10740 Jun 10, 2026
s2n-quic 1.8.2+ Unbounded CRYPTO frame reassembler DoS Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets. To remediate this issue, users should upgrade to v1.8.2.
S2n Quic
CVE-2026-11417 Jun 10, 2026
OS Command Injection NodejsFunction bundling in aws-cdk-lib <2.245.0 OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) might allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the threat actor to control the value of one or more of the affected bundling properties in the CDK application. To remediate this issue, users should upgrade to aws-cdk-lib 2.245.0 (2.246.0 on Windows) or later.
Aws Cloud Development Kit Library
CVE-2026-11393 Jun 08, 2026
CVE-2026-11393: AgentCore CLI v<0.14.2 RCE via triplequote code gen Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS account, via a crafted collaborationInstruction stored on a Bedrock Agent collaborator and later processed by that other user during agent import. To remediate this issue, users should upgrade to version 0.14.2.
Agentcore Cli
CVE-2026-11401 Jun 05, 2026
AWS Adv Go Wrapper GDBP Untrusted Search Path Escalation An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through the affected wrapper. To remediate this issue, users should upgrade to the AWS Advanced Go Wrapper release 2026-05-26
Aws Advanced Go Wrapper
CVE-2026-11400 Jun 05, 2026
AWS Advanced JDBC Wrapper 4.0.0 GlobalDatabasePlugin Search Path Escalation An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through an affected wrapper. To remediate this issue, users should upgrade to AWS Advanced JDBC Wrapper version 4.0.1.
Aws Advanced Jdbc Wrapper
CVE-2026-10584 Jun 02, 2026
Graph Explorer v<3.0.1 HTTP Fallback Enables HTTPS Interception Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS. To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
Graph Explorer
CVE-2026-10591 Jun 02, 2026
Amazon Kiro IDE <0.11 File Write CA Remote Exec Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via crafted instructions that cause writes to execution-sensitive paths (such as .vscode/tasks.json), enabling auto-execution on folder open. To remediate this issue, users should upgrade to Kiro IDE version 0.11 or later.
Kiro Ide
CVE-2026-9291 May 22, 2026
Amazon Braket SDK 1.117.0 Fix: Insecure Deserialization (Remote Exec) Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. We recommend you upgrade to amazon-braket-sdk version 1.117.0 or later.
Amazon Braket Python Sdk
CVE-2026-9255 May 22, 2026
Kiro CLI <1.28.0: Missing input validation allows arbitrary tool exec via stdin Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by crafting content that is piped to kiro-cli via stdin. We recommend you to upgrade to kiro-cli version 1.28.0 or later.
Kiro Cli
CVE-2026-9133 May 20, 2026
Amazon MQ rabbitmq-aws <0.2.1: Debug ARN allows remote file read Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.
Rabbitmq Aws
CVE-2026-8838 May 18, 2026
Amazon Redshift Python Driver eval() Vulnerability in vector_in() before 2.1.14 Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate this issue, users should upgrade to version 2.1.14.
Amazon Redshift Connector Python
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.