AWS C Event Stream Streaming Decoder Stack Buffer Overflow
UnratedCVE-2026-5190 · Published Mar 31, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when ...
Affected versions
Details and references
Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when client communicates using event-stream protocol with a third party operating a server. To avoid the issue, ensure that the server being communicated with is trusted. AWS servers would not trigger this issue. Reference: CVE-2026-5190 GHSA-xvjw-fjq5-68hf We would like to thank 1seal.org for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-011-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-5190 - AWS C Event Stream Streaming Decoder Stack Buffer Overflow Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when client communicates using event-stream protocol with a third party operating a server. To avoid the issue, ensure that the server being communicated with is trusted.
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 3 | Issues with Amazon Athena ODBC Driver | Unrated | No fix yet |
| Apr 2 | Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme | Unrated | No fix yet |
| Mar 26 | Defense in depth enhancement for CloudFront signing utility in AWS Tools for PowerShell | High7.7 | 4.1.1008+1 more |
| Mar 26 | Defense in depth enhancement for CloudFront signing utility in AWS SDK for .NET | High7.7 | 3.7.510.7+1 more |
| Mar 25 | Defense in depth enhancement for CloudFront signing utility | High7.7 | No fix yet |
| Mar 25 | Defense in depth enhancement for CloudFront signing utility in AWS SDK for Java v2 | High7.7 | 2.41.30 |