Memory Corruption Issue in AWS Common Runtime's HTTP Library
CVE-2026-12043
8.7HIGH
What is CVE-2026-12043?
The vulnerability involves improper management of HPACK dynamic table size updates in the AWS Common Runtime's aws-c-http library. This flaw could allow a remote attacker controlling a server to generate a series of intentionally crafted HTTP/2 HEADERS frames, resulting in memory corruption on the client application that connects to the affected server. The potential consequences include arbitrary code execution, which can severely compromise the security and integrity of the affected systems. It is crucial for users to upgrade to aws-c-http version 0.11.0 to mitigate this risk.
Affected Version(s)
aws-c-http 0.4.22 <= 0.10.15
