Panic in Event Stream Header Decoder in Amazon AWS SDK for Go
CVE-2026-89090

8.2HIGH

Key Information:

Vendor

Aws

Vendor
CVE Published:
11 September 2026

What is CVE-2026-89090?

An unrecovered panic in the event stream header decoder of the Amazon AWS SDK for Go v2 can allow attackers to terminate the application process. This issue is triggered by a crafted event stream response frame containing a header value type that falls outside the valid range. Users are advised to upgrade to release-2026-03-23 or later and ensure any forked or derivative code is patched properly to mitigate this risk.

Affected Version(s)

AWS SDK for Go v2 0 < 2026-03-23

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.