Skip to content
AWSAWS-2026-011

AWS C Event Stream Streaming Decoder Stack Buffer Overflow

UnratedCVE-2026-5190 · Published Mar 31, 2026 · updated Sep 25, 2026

Bulletin ID:  2026-011-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when ...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID:  2026-011-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when client communicates using event-stream protocol with a third party operating a server. To avoid the issue, ensure that the server being communicated with is trusted. AWS servers would not trigger this issue. Reference: CVE-2026-5190 GHSA-xvjw-fjq5-68hf We would like to thank 1seal.org for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-011-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-5190 - AWS C Event Stream Streaming Decoder Stack Buffer Overflow Bulletin ID:  2026-011-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 03/31/2026 10:15 AM PST Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190 . AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: aws-c-event-stream aws-iot-device-sdk-cpp-v2 aws-iot-device-sdk-java-v2 aws-iot-device-sdk-python-v2 aws-iot-device-sdk-js-v2 aws-sdk-swift aws-sdk-cpp Resolution: This issue has been addressed in aws-c-event-stream version 0.6.0 , aws-iot-device-sdk-cpp-v2 version 1.42.1 , aws-iot-device-sdk-java-v2 version 1.30.1 , aws-iot-device-sdk-python-v2 version 1.28.2 , aws-iot-device-sdk-js-v2 version 1.25.1 , aws-sdk-swift 1.6.70 , and aws-sdk-cpp version 1.11.764 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: The issue can only occur when client communicates using event-stream protocol with a third party operating a server. To avoid the issue, ensure that the server being communicated with is trusted.

Severity from
no source yet

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.