Panic in Event Stream Header Decoder in Amazon AWS SDK for Go
CVE-2026-89090
8.2HIGH
What is CVE-2026-89090?
An unrecovered panic in the event stream header decoder of the Amazon AWS SDK for Go v2 can allow attackers to terminate the application process. This issue is triggered by a crafted event stream response frame containing a header value type that falls outside the valid range. Users are advised to upgrade to release-2026-03-23 or later and ensure any forked or derivative code is patched properly to mitigate this risk.
Affected Version(s)
AWS SDK for Go v2 0 < 2026-03-23
