aws
Latest CVEs
The 15 most recently published vulnerabilities affecting aws.
- CVE-2026-94450Potential denial of service when configured to send Retry packets in s2n-quic7.5
- CVE-2026-92943Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python8.1
- CVE-2026-86831Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS8.7
- CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center7.2
- CVE-2026-89332Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration5.5
- CVE-2026-89090Denial of service in the event stream header decoder in AWS SDK for Go v25.9
- CVE-2026-18061Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin5.9
- CVE-2026-89066OS command injection in the task synthesis component in projen7.8
- CVE-2026-89065Relative path traversal in the generated file manifest cleanup component in projen7.1
- CVE-2026-89049Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent9.9
- CVE-2026-87913Missing S3 bucket ownership verification in the AWS Security Agent MCP server5.9
- CVE-2026-87912Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops5.9
- CVE-2026-87911Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server9.6
- CVE-2026-85788Incomplete list of disallowed inputs in awslabs mysql-mcp-server5.5
- CVE-2026-84942Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards8.7