


Perceptive Security
SOC/SIEM Consultancy

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruptio…
Published:
30 maart 2026 om 22:00:00
Alert date:
31 maart 2026 om 19:02:07
Source:
nvd.nist.gov
Cloud & Virtualization, Supply Chain & Dependencies
Out-of-bounds write vulnerability in aws-c-event-stream streaming decoder component before version 0.6.0. Third-party servers can exploit this flaw to cause memory corruption leading to arbitrary code execution on client applications processing crafted event-stream messages. The vulnerability affects client applications that process event streams from untrusted servers. Memory corruption can lead to complete compromise of the client system. Users should upgrade to version 0.6.0 or later to remediate this high-severity issue.
Technical details
Mitigation steps:
Affected products:
aws-c-event-stream
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5190
https://aws.amazon.com/security/security-bulletins/2026-011-aws/
https://github.com/awslabs/aws-c-event-stream/releases/tag/v0.6.0
https://github.com/awslabs/aws-c-event-stream/security/advisories/GHSA-xvjw-fjq5-68hf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
