amazon
Latest CVEs
The 15 most recently published vulnerabilities affecting amazon.
- CVE-2026-94384Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda8.1
- CVE-2023-32803The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists bec...7.5
- CVE-2026-89332Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration5.5
- CVE-2026-18061Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin5.9
- CVE-2026-85228Integer overflow in tensor buffer validation in Deep Java Library9.1
- CVE-2026-85787An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server6.5
- CVE-2026-85786Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java7.5
- CVE-2026-85656OS command injection in Amazon log4j-cve-2021-44228-hotpatch7.8
- CVE-2026-85654Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server7.8
- CVE-2026-84851Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.67.5
- CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination8.8
- CVE-2026-81849Path traversal in the aws:downloadContent plugin in amazon-ssm-agent8.8
- CVE-2026-81838Zip Slip Arbitrary File Write in AWS diagram-as-code (awsdac)7.1
- CVE-2026-78379Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools8.1
- CVE-2026-77237Missing type validation in xQueueAddToSet in FreeRTOS-Kernel6.5