在 2026-03-23 之前版本的 Amazon AWS SDK for Go v2 中,事件流(event stream)头部解码器中存在一个未恢复的 panic(panic),可能导致未经身份验证的远程攻击者通过构造一个包含超出有效范围的头部值类型的事件流响应帧,从而终止正在消费事件流的应用进程。 要修复此问题,用户应升级到 2026-03-23 或更高版本,并修补任何分叉或衍生代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS SDK for Go v2 | 0 ~ 2026-03-23 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89066 | 7.8 HIGH | OS command injection in the task synthesis component in projen |
| CVE-2026-89065 | 7.1 HIGH | Relative path traversal in the generated file manifest cleanup component in projen |
| CVE-2026-18061 | 5.9 MEDIUM | Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper Remote |
No comments yet