2026-110-AWSHigh
CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate.
Impacted versions:
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.