Skip to content
AWSGHSA-mxm9-xpf9-x66x

Out-of-bounds read in the Base64 decoder in the AWS SDK for C++

Medium5.3CVE-2026-19643 · Published Aug 12, 2026

## Summary The AWS SDK for C++ is an open-source library that provides C++ developers with APIs for AWS services. Certain inputs to the Base64 decoder in the SDK's core library, on some platforms, might cause the decoder to read outside the bounds of its decode table. ## Impact Certain inputs to the Base64 decoder, on some platforms, might cause the decoder to read outside the bounds of its decode table, which might crash the process performing the decode. The decoder is reachable from the generated C++ service clients, which use it for a variety of features. Impacted versions: <= 1.11.861 ## Patches This issue has been addressed in AWS SDK for C++ version 1.11.862. The SDK's Base64 implementation now delegates to the implementation in the AWS Common Runtime (`aws-crt-cpp`). We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Customers who vendor or statically link the SDK should confirm that their build consumes the updated `aws-crt-cpp` submodule, not only the updated SDK sources. ## Workarounds There is no configuration or runtime option that avoids this issue. Upgrading is required. ## Refer...

GitHub advisory

Affected versions

PackageAffectedFixed in
aws-cpp-sdk-core
Product
< 1.11.8621.11.862
Details and references

## Summary The AWS SDK for C++ is an open-source library that provides C++ developers with APIs for AWS services. Certain inputs to the Base64 decoder in the SDK's core library, on some platforms, might cause the decoder to read outside the bounds of its decode table. ## Impact Certain inputs to the Base64 decoder, on some platforms, might cause the decoder to read outside the bounds of its decode table, which might crash the process performing the decode. The decoder is reachable from the generated C++ service clients, which use it for a variety of features. Impacted versions: <= 1.11.861 ## Patches This issue has been addressed in AWS SDK for C++ version 1.11.862. The SDK's Base64 implementation now delegates to the implementation in the AWS Common Runtime (`aws-crt-cpp`). We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Customers who vendor or statically link the SDK should confirm that their build consumes the updated `aws-crt-cpp` submodule, not only the updated SDK sources. ## Workarounds There is no configuration or runtime option that avoids this issue. Upgrading is required. ## References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. ## Acknowledgement We would like to thank Lucas Carvalho Cordeiro (@lucasccordeiro) and Rafael Sa Menezes (@rafaelsamenezes) of the University of Manchester for collaborating on this issue through the coordinated vulnerability disclosure process.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-125

More AWS advisories

All AWS
Advisory
Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
UnratedAug 18
OpenSearch SQL Plugin - Async Query Validation Bypass
UnratedAug 13
AWS: out-of-bounds write
UnratedAug 12
Missing Input Validation in OpenSearch Security Analytics Plugin
UnratedAug 12
Missing Authorization in OpenSearch Alerting Plugin
UnratedAug 12
Insecure direct object reference in Strands Agents Tools memory tools
UnratedAug 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.