Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Amazon Web Services — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting Amazon Web Services. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services provides scalable cloud computing infrastructure and services for businesses globally. Historically, common vulnerabilities include remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from misconfigurations or service-specific weaknesses. While AWS maintains robust security controls, notable incidents include the 2020 Capital One breach where a misconfigured S3 bucket exposed 100 million customer records, and the 2023 vulnerability in AWS Lambda that allowed privilege escalation. The platform's extensive attack surface and complex permission models require careful configuration to prevent unauthorized access and data exposure.

CVE ID Title CVSS Severity Published
CVE-2026-12958 Arbitrary file write in Language Servers for AWS — Language Servers for AWS CWE-61 7.8 High 2026-06-23
CVE-2026-12957 Arbitrary Code Execution in Language Servers for AWS — Language Servers for AWS CWE-732 7.8 High 2026-06-23
CVE-2022-0071 Hotdog Container Escape — Hotdog CWE-250 8.8 High 2022-04-19
CVE-2022-0070 Log4j hot patch package privilege escalation — log4j-cve-2021-44228-hotpatch CWE-250 8.8 High 2022-04-19
CVE-2021-3101 Hotdog Container Escape — Hotdog CWE-250 8.8 High 2022-04-19
CVE-2021-3100 Log4j hot patch package privilege escalation — log4j-cve-2021-44228-hotpatch CWE-250 8.8 High 2022-04-19
CVE-2021-40831 Missing SNI validation and inconsistent CA override function behavior within AWS IoT Device SDKs on Apple devices — AWS IoT Device SDK v2 for Java 6.3 Medium 2021-11-22
CVE-2021-40830 Inconsistent CA override function behavior within AWS IoT Device SDKs on Unix systems — AWS IoT Device SDK v2 for Java 6.3 Medium 2021-11-22
CVE-2021-40829 TLS hostname validation issues within AWS IoT Device SDKs on macOS — AWS IoT Device SDK v2 for Java 6.3 Medium 2021-11-22
CVE-2021-40828 TLS hostname validation issues within AWS IoT Device SDKs on Windows — AWS IoT Device SDK v2 for Java 6.3 Medium 2021-11-22

This page lists every published CVE security advisory associated with Amazon Web Services. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.