AWS Security Bulletins
Amazon Web Services security advisories.
134 advisories tracked · showing 100
- Sep 17, 20262026-115-AWSHighCVE-2026-92943
CVE-2026-92943 - Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
- Sep 16, 20262026-113-AWSHighCVE-2026-86831
CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
- Sep 14, 20262026-112-AWSHighCVE-2026-86830
CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
- Sep 11, 20262026-111-AWSHighCVE-2026-89332
CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
- Sep 11, 20262026-110-AWSHighCVE-2026-89090
CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
- Sep 11, 20262026-109-AWSHighCVE-2026-18061
CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
- Sep 11, 20262026-108-AWSHighCVE-2026-89065, CVE-2026-89066
CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
- Sep 10, 20262026-107-AWSHighCVE-2026-89049
CVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent
- Sep 10, 20262026-106-AWSHighCVE-2026-85228
CVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library
- Sep 9, 20262026-105-AWSHighCVE-2026-87912, CVE-2026-87913
CVE-2026-87912 and CVE-2026-87913: Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops and MCP Server
- Sep 9, 20262026-104-AWSCVE-2026-87911
CVE-2026-87911
- Sep 9, 20262026-103-AWSHighCVE-2026-85788
CVE-2026-85788 - Issue with awslabs mysql-mcp-server
- Sep 8, 20262026-102-AWSHighCVE-2026-84942
CVE-2026-84942 - Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
- Sep 4, 20262026-101-AWSHighCVE-2026-85787
CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope
- Sep 4, 20262026-097-AWSHighCVE-2026-85654
CVE-2026-85654 - Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
- Sep 4, 20262026-100-AWSHighCVE-2026-85786, CVE-2026-75936
CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java
- Sep 4, 20262026-099-AWSHighCVE-2026-85781
CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
- Sep 4, 20262026-098-AWSHighCVE-2021-44228, CVE-2026-85656
CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
- Sep 3, 20262026-096-AWSHighCVE-2026-85028
CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit
- Sep 3, 20262026-095-AWSHighCVE-2026-85012
CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK
- Sep 2, 20262026-094-AWSHighCVE-2026-84851
CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
- Sep 1, 20262026-093-AWSHighCVE-2026-83551
CVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
- Aug 31, 20262026-092-AWSHighCVE-2026-83497
CVE-2026-83497 - OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
- Aug 28, 20262026-091-AWSHighCVE-2026-81849
CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
- Aug 28, 20262026-090-AWSHighCVE-2026-81838
CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)
- Aug 25, 20262026-089-AWSHighCVE-2026-78379
CVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool
- Aug 21, 20262026-088-AWSHighCVE-2026-77811
CVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
- Aug 21, 20262026-087-AWSHighCVE-2026-77810
CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
- Aug 21, 20262026-086-AWSHighCVE-2026-77235, CVE-2026-77236 +2
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237
- Aug 20, 20262026-085-AWSHighCVE-2026-18420
CVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin
- Aug 20, 20262026-084-AWSHighCVE-2026-75910
CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
- Aug 18, 20262026-083-AWSHighCVE-2026-75935, CVE-2026-75936
CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service
- Aug 18, 20262026-082-AWSHighCVE-2026-75897
CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
- Aug 13, 20262026-081-AWSHighCVE-2026-18428
CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass
- Aug 13, 20262026-079-AWSHighCVE-2026-18952
CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin
- Aug 12, 20262026-080-AWSHighCVE-2026-19642, CVE-2026-19643
CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
- Aug 12, 20262026-078-AWSHighCVE-2026-19311
CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin
- Aug 6, 20262026-077-AWSHighCVE-2026-19111
CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools
- Aug 5, 20262026-076-AWSHighCVE-2026-18954
CVE-2026-18954 - Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server
- Aug 5, 20262026-075-AWSHighCVE-2026-18953
CVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server
- Aug 4, 20262026-074-AWSHighCVE-2026-18656, CVE-2026-18657
CVE-2026-18656 & CVE-2026-18657 - Issue with Kiro IDE and CLI - Executable Resolution from Untrusted Project Directory on Windows
- Aug 4, 20262026-073-AWSHighCVE-2026-18830
CVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation
- Aug 3, 20262026-072-AWSHighCVE-2026-18733
CVE-2026-18733 - Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- Aug 3, 20262026-071-AWSHighCVE-2026-18654
CVE-2026-18654 - Disabled SSH host key verification in AWS CLI EMR helper commands
- Aug 3, 20262026-070-AWSHighCVE-2026-18655
CVE-2026-18655 - Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection
- Jul 31, 20262026-069-AWSHighCVE-2026-18394
CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
- Jul 31, 20262026-068-AWSCVE-2026-18481
CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
- Jul 31, 20262026-066-AWSCVE-2025-4318
Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react
- Jul 31, 20262026-067-AWSCVE-2026-18140
CVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers
- Jul 23, 20262026-065-AWSHighCVE-2026-16796
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- Jul 23, 20262026-064-AWSHighCVE-2026-16756
CVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
- Jul 23, 20262026-063-AWSHighCVE-2026-16584
CVE-2026-16584 - AWS API MCP Server Security Policy Bypass via Startup Failure
- Jul 21, 20262026-062-AWSHighCVE-2026-16317, CVE-2026-16318
CVE-2026-16317 and CVE-2026-16318: Issues with s2n-tls: an open-source implementation of the TLS/SSL protocols
- Jul 21, 20262026-061-AWSHighCVE-2026-15957
CVE-2026-15957 - Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes
- Jul 17, 20262026-060-AWSHighCVE-2026-15415
CVE-2026-15415 - Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server
- Jul 17, 20262026-059-AWSHighCVE-2026-12283
CVE-2026-12283 - Issue with Athena Federated Query Synapse Connector
- Jul 16, 20262026-057-AWSHighCVE-2026-15895
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
- Jul 16, 20262026-058-AWSHighCVE-2026-15737
CVE-2026-15737 - Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK
- Jul 15, 20262026-056-AWSHighCVE-2026-15746
CVE-2026-15746 - Credential disclosure in Strands Agents Tools elasticsearch_memory tool
- Jul 14, 20262026-055-AWSHighCVE-2026-15738
CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Priority Ordering
- Jul 14, 20262026-054-AWSHighCVE-2026-15643
CVE-2026-15643 - AWS HealthLake MCP Server SSRF via Unvalidated Pagination URL
- Jul 7, 20262026-053-AWSHighCVE-2026-14904
CVE-2026-14904 - Improper Link Resolution in Auth.GetUserPrivateKey in AWS Research and Engineering Studio
- Jul 6, 20262026-052-AWSHighCVE-2026-14471
CVE-2026-14471 - Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry
- Jul 1, 20262026-051-AWSHighCVE-2026-14265
CVE-2026-14265- Deserialization of Untrusted Data in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
- Jul 1, 20262026-050-AWSHighCVE-2026-13760
CVE-2026-13760 - OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib
- Jul 1, 20262026-049-AWSHighCVE-2026-13769
CVE-2026-13769 – Insecure file permissions in AWS CLI
- Jun 29, 20262026-048-AWSHighCVE-2026-13762, CVE-2026-13763
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
- Jun 23, 20262026-047-AWSHighCVE-2026-12957, CVE-2026-12958
CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
- Jun 19, 20262026-046-AWSHighCVE-2026-50195, CVE-2026-53488 +3
Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262
- Jun 17, 20262026-044-AWSHighCVE-2026-12530
CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- Jun 15, 20262026-045-AWSHighCVE-2026-11931
CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE
- Jun 12, 20262026-043-AWSHighCVE-2026-12043
CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http
- Jun 10, 20262026-042-AWSHighCVE-2026-10740
CVE-2026-10740 - Excessive memory allocation in s2n-quic
- Jun 10, 20262026-041-AWSHighCVE-2026-10740, CVE-2026-11417
CVE-2026-10740 - Excessive memory allocation in s2n-quic
- Jun 8, 20262026-040-AWSHighCVE-2026-11393
CVE-2026-11393 - Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
- Jun 5, 20262026-039-AWSHighCVE-2026-11400, CVE-2026-11401
CVE-2026-11400 and CVE-2026-11401
- Jun 2, 20262026-038-AWSHighCVE-2026-10584
CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer
- Jun 2, 20262026-037-AWSHighCVE-2026-10591
CVE-2026-10591 - Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
- May 22, 20262026-036-AWSHighCVE-2026-9291
CVE-2026-9291 - Insecure Deserialization in Amazon Braket SDK Job Results Processing
- May 22, 20262026-035-AWSHighCVE-2026-9255
CVE-2026-9255 - Tool Execution Without Authorization via Piped Stdin in Kiro CLI
- May 20, 20262026-034-AWSHighCVE-2026-9133
CVE-2026-9133 - Arbitrary file read in rabbitmq-aws plugin
- May 18, 20262026-033-AWSHighCVE-2026-8838
CVE-2026-8838 - Remote Code Execution in amazon-redshift-python-driver
- May 15, 20262026-032-AWSHighCVE-2026-8686
CVE-2026-8686 - Heap out-of-bounds read in coreMQTT MQTT5 property parsing
- May 15, 20262026-031-AWSHighCVE-2026-8597, CVE-2026-8596
Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues (CVE-2026-8596 & CVE-2026-8597)
- May 14, 20262026-030-AWSHighDisclosed before NVD
Ongoing updates on Copy.fail and variants
- May 14, 20262026-029-AWSHighCVE-2026-46300, CVE-2026-43284
Fragnesia Local Privilege Escalation report via ESP-in-TCP in the Linux Kernel
- May 11, 20262026-027-AWSHighCVE-2026-31431
Dirty Frag and other issues in Amazon Linux kernels
- May 8, 20262026-028-AWSHighCVE-2026-8178
CVE-2026-8178 - Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver
- May 7, 20262026-026-AWSHighCVE-2026-31431
CVE-2026-31431
- May 4, 20262026-025-AWSHighCVE-2026-7791
CVE-2026-7791 - Local Privilege Escalation via TOCTOU Race Condition in Amazon WorkSpaces Skylight Agent
- May 1, 20262026-024-AWSHighCVE-2026-7461
CVE-2026-7461 - OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials
- Apr 29, 20262026-023-AWSHighCVE-2026-7425, CVE-2026-7426
Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues
- Apr 29, 20262026-022-AWSHighCVE-2026-7424
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
- Apr 29, 20262026-021-AWSHighCVE-2026-7422, CVE-2026-7423
Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow
- Apr 27, 20262026-020-AWSHighCVE-2026-7191
CVE-2026-7191- Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS
- Apr 24, 20262026-019-AWSHighCVE-2026-6966, CVE-2026-6967 +1
Issues in tough library and tuftool CLI utility
- Apr 24, 20262026-018-AWSHighCVE-2026-6911, CVE-2026-6912
Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912
- Apr 20, 20262026-017-AWSHighCVE-2026-6550
CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
- Apr 17, 20262026-016-AWSHighCVE-2026-6437
CVE-2026-6437 - Mount Option Injection in Amazon EFS CSI Driver
- Apr 14, 20262026-015-AWSHighCVE-2026-5747
CVE-2026-5747 - Out-of-bounds Write in Firecracker virtio-pci Transport