Skip to content

AWS security advisories

167 advisories · 21 critical or high in 12 months · latest Sep 25

60 of 167 advisories

Advisory
REMOVE_BASE_PATH strips every leading repetition of the base path, not just one
LowSep 25
Type confusion in AWS pgcollection allows remote code execution
High8.8Sep 24
Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
High8.8Sep 22
Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...
High8.0Sep 22
HTTPS Fallback to HTTP in Graph Explorer
Medium5.9Sep 22
Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
Critical9.0Sep 22
Excessive memory allocation in s2n-quic
Medium5.3Sep 22
Insecure Permissions on Authentication Token Cache File in Kiro IDE
Medium5.5Sep 22
Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Critical9.8Sep 22
Insecure file permissions in AWS CLI
Medium5.5Sep 22
Authenticated SQL injection in the metrics-service retention policy subsystem of...
High8.1Sep 22
Heap double-free in AWS Common Runtime aws-c-http
UnratedSep 22
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK...
UnratedSep 22
Issues in Language Servers for AWS and Amazon Q Developer Plugins
UnratedSep 22
Deserialization of Untrusted Data in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
UnratedSep 22
Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492...
UnratedSep 22
OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib
UnratedSep 22
Potential denial of service when configured to send Retry packets in s2n-quic
UnratedSep 22
Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
UnratedSep 22
Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python
UnratedSep 17
Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS
UnratedSep 16
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM...
UnratedSep 14
Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
UnratedSep 11
Denial of service in the event stream header decoder in AWS SDK for Go v2
UnratedSep 11
XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
UnratedSep 11
Issue with projen - Path traversal and OS command injection
UnratedSep 11
Server-side request forgery in the Session Manager port forwarding functionality in AWS...
UnratedSep 10
Integer overflow in tensor buffer validation in Deep Java Library
UnratedSep 10
Missing S3 bucket ownership verification in the AWS Security Agent plugin for...
UnratedSep 10
Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows...
UnratedSep 9
Issue with awslabs mysql-mcp-server
UnratedSep 9
Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards
UnratedSep 8
AWS log4j-cve-2021-44228-hotpatch: command injection
High8.5Sep 4
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs...
UnratedSep 4
Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon...
UnratedSep 4
Unverified access point ownership in Amazon EFS CSI Driver
UnratedSep 4
Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server
UnratedSep 4
Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development...
UnratedSep 3
OS command injection in the Amazon CodeCatalyst blueprints SDK
UnratedSep 3
Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6
UnratedSep 2
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK
UnratedSep 1
OpenSearch SQL Plugin - Unrestricted Java Deserialization in Cursor Pagination
UnratedAug 31
Path traversal in the aws:downloadContent plugin in amazon-ssm-agent
UnratedAug 28
Zip Slip path traversal in awsdac (diagram-as-code)
UnratedAug 27
Consent bypass in Strands Agents Tools python_repl tool
UnratedAug 25
Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards
UnratedAug 21
Issue with Athena Federated Query Neptune Connector
UnratedAug 21
Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236...
UnratedAug 21
Issue with Athena Federated Query Clickhouse Connector
UnratedAug 20
Issue with Amazon ion-java - Memory-amplification denial of service
UnratedAug 18
Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
UnratedAug 18
OpenSearch SQL Plugin - Async Query Validation Bypass
UnratedAug 13
Out-of-bounds read in the Base64 decoder in the AWS SDK for C++
Medium5.3Aug 12
AWS: out-of-bounds write
UnratedAug 12
Missing Input Validation in OpenSearch Security Analytics Plugin
UnratedAug 12
Missing Authorization in OpenSearch Alerting Plugin
UnratedAug 12
Insecure direct object reference in Strands Agents Tools memory tools
UnratedAug 6
Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB...
UnratedAug 5
Improper limitation of a pathname in AWS Transform MCP Server
UnratedAug 5
AWS: code execution
UnratedAug 4
About AWS

Security advisories AWS publishes for its own products.

AWS elsewhere on fru.dev: Acquisitions · Paydays · Releases · Repos · TechConf · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.