Authentication Flaw in simalexan API Gateway Endpoint Affecting Email Functionality
CVE-2026-90513
6.9MEDIUM
What is CVE-2026-90513?
A vulnerability has been identified in the simalexan api-lambda-send-email-ses product affecting the SES.sendEmail function within the API Gateway Endpoint component. This flaw arises from improper handling of parameters, including toEmails, ccEmails, replyToEmails, subject, and message, leading to a lack of necessary authentication. The issue allows potential attackers to exploit this vulnerability remotely. Due to the product's rolling release model, detailed versioning information on affected or patched releases remains unavailable. Despite early notification of this issue through an issue report, the project maintainers have yet to provide a response.
Affected Version(s)
api-lambda-send-email-ses bda6869aa81371d1e872242e74fe7d953edb818d
