Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AWS — Vulnerabilities & Security Advisories 115

Browse all 115 CVE security advisories affecting AWS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services operates as a comprehensive cloud computing platform, providing infrastructure, storage, and networking solutions to enterprises globally. With 68 recorded Common Vulnerabilities and Exposures, the platform’s security landscape reflects the complexity of its vast ecosystem. Historically, identified flaws have predominantly involved cross-site scripting, remote code execution, and privilege escalation issues, often stemming from misconfigurations or third-party component dependencies rather than core hypervisor failures. Notable incidents have occasionally highlighted risks associated with shared responsibility models, where customer-side errors led to data exposure. Despite these challenges, AWS maintains robust isolation mechanisms and continuous monitoring protocols. The frequency of vulnerabilities underscores the necessity for rigorous patch management and strict access controls. Users must remain vigilant, recognizing that while the underlying infrastructure is hardened, the security of deployed workloads largely depends on proper configuration and adherence to best practices within the shared responsibility framework.

Found 3 results / 115Clear Filters
MediumGHSA-xxx3-prfc-69cx2026-08-13
Out-of-bounds write in the Base64 decoder in the AWS SDK for C++ · Advisory · aws/aws-sdk-cpp · GitHub
HighCVE-2026-189532026-08-06
Improper limitation of a pathname in AWS Transform MCP Server · Advisory · awslabs/mcp · GitHub
High2026-08-01
fix(security): prevent stored XSS via participant_url by wuchenna · Pull Request #168 · aws/aws-ops-wheel · GitHub
HighCVE-2024-14412026-08-01
Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft · Advisory · aws/aws-ops-wheel · G
CriticalCVE-2026-184812026-08-01
CVE-2026-18481- Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
HighCVE-2026-181402026-07-31
2026-067-AWS
UnknownCVE-2026-167962026-07-24
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
HighCVE-2026-167962026-07-24
CVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() ·
HighGHSA-jxpx-qmx7-gjgx2026-07-24
Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowlor
Unknown2026-07-18
Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server · Advisory · awslabs/mcp ·
MediumCVE-2026-123832026-07-18
Issue with Athena Federated Query Synapse Connector · Advisory · awslabs/aws-athena-query-federation · GitHub
HighCVE-2024-157372026-07-17
Sensitive content disclosure via OpenTelemetry spans in bedrock-agentcore-sdk-python · Advisory · aws/bedrock-agentcore-
HighCVE-2026-157462026-07-16
Credential disclosure via LLM-controllable connection parameters in Strands Agents Tools elasticsearch_memory tool · Adv
HighCVE-2026-157382026-07-15
CVE-2026-15738 - Issue with AWS Load Balancer Controller Cross-Namespace Traffic Interception via HTTPRoute/GRPCRoute Pr
High2026-07-08
Release 2026.06 · aws/res · GitHub
High2026-07-02
CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
HighCVE-2026-137892026-07-02
Overly permissive File Permissions in AWS CLI · Advisory · aws/aws-cli · GitHub
UnknownCVE-2026-129572026-06-27
CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins
HighCVE-2026-125302026-06-18
CVE-2026-12530 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
HighCVE-2026-114002026-06-13
CVE-2026-11400 and CVE-2026-11401 - Privilege Escalation in Aurora PostgreSQL using AWS Advanced JDBC Wrapper, AWS Advan

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with AWS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.