Out-of-Bounds Read Vulnerability in Amazon aws-sdk-cpp
CVE-2026-19643

6MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
12 August 2026

What is CVE-2026-19643?

An out-of-bounds read vulnerability was discovered in the Base64 decoder of Amazon's aws-sdk-cpp, which could potentially allow remote authenticated users to provoke an application's crash by supplying specially crafted Base64-encoded input. This issue affects specific platform versions earlier than 1.11.862. Users are advised to upgrade to this version immediately to mitigate any associated risks.

Affected Version(s)

aws-sdk-cpp 0 <= 1.11.861

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

University of Manchester
.