Memory Corruption Issue in AWS Common Runtime's HTTP Library
CVE-2026-12043

8.7HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
12 June 2026

What is CVE-2026-12043?

The vulnerability involves improper management of HPACK dynamic table size updates in the AWS Common Runtime's aws-c-http library. This flaw could allow a remote attacker controlling a server to generate a series of intentionally crafted HTTP/2 HEADERS frames, resulting in memory corruption on the client application that connects to the affected server. The potential consequences include arbitrary code execution, which can severely compromise the security and integrity of the affected systems. It is crucial for users to upgrade to aws-c-http version 0.11.0 to mitigate this risk.

Affected Version(s)

aws-c-http 0.4.22 <= 0.10.15

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.