Excessive memory allocation in s2n-quic
Medium5.3CVE-2026-10740 · Published Sep 22, 2026
Bulletin ID: 2026-041-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 10:45 AM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified CVE-2026-11417 , an OS command injection issue in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) that may allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the actor to control the value of one or more of the affected bundling properties in the CDK application. Impacted versions: Resolution: This issue has been addressed in aws-cdk-lib version 2.245.0 (2.246.0 on Windows). We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Ensure values passed to NodejsFunction bundling properties come only from trusted sources and audit third-par...
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Sep 26 | Severity: Unrated to Medium |
Details and references
Bulletin ID: 2026-041-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 10:45 AM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified CVE-2026-11417 , an OS command injection issue in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) that may allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the actor to control the value of one or more of the affected bundling properties in the CDK application. Impacted versions: Resolution: This issue has been addressed in aws-cdk-lib version 2.245.0 (2.246.0 on Windows). We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Ensure values passed to NodejsFunction bundling properties come only from trusted sources and audit third-party constructs and pull requests that set them. Upgrading to a fixed version is the recommended remediation. References: CVE-2026-11417 GHSA-999r-qq7v-r334 Acknowledgement: We would like to thank the external reporter Hesham Ashraf who collaborated on this issue through the AWS Vulnerability Disclosure Program (coordinated vulnerability disclosure process). Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-041-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-11417 - OS Command Injection in aws-cdk-lib NodejsFunction bundling Bulletin ID: 2026-041-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/10/2026 10:45 AM PDT Description: AWS CDK (aws-cdk-lib) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudFormation. We identified CVE-2026-11417 , an OS command injection issue in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) that may allow an actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) to execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This issue requires the actor to control the value of one or more of the affected bundling properties in the CDK application. Impacted versions: Resolution: This issue has been addressed in aws-cdk-lib version 2.245.0 (2.246.0 on Windows). We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Ensure values passed to NodejsFunction bundling properties come only from trusted sources and audit third-party constructs and pull requests that set them. Upgrading to a fixed version is the recommended remediation. References: CVE-2026-11417 GHSA-999r-qq7v-r334 Acknowledgemen
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- NVD
- Also known as
- CVE-2026-11417
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | High8.8 | No fix yet |
| Sep 22 | Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible... | High8.0 | No fix yet |
| Sep 22 | HTTPS Fallback to HTTP in Graph Explorer | Medium5.9 | No fix yet |
| Sep 22 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Critical9.0 | No fix yet |
| Sep 22 | Issue with HTTP/2 multi-frame request body inspection in AWS WAF | Critical9.8 | No fix yet |
| Sep 22 | Authenticated SQL injection in the metrics-service retention policy subsystem of... | High8.1 | No fix yet |