Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Amazon — Vulnerabilities & Security Advisories 54

Browse all 54 CVE security advisories affecting Amazon. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon operates primarily as a global e-commerce platform and cloud computing provider, offering extensive infrastructure services alongside retail operations. With thirty-six recorded Common Vulnerabilities and Exposures, the entity has historically faced risks associated with remote code execution, cross-site scripting, and privilege escalation, reflecting the complexity of its distributed architecture. Security assessments indicate that while the core infrastructure maintains robust controls, peripheral services and third-party integrations often present attack vectors. Notable incidents have included data exposure events and service disruptions, prompting continuous hardening of access controls and encryption standards. The organization’s scale necessitates rigorous monitoring, yet the sheer volume of endpoints and APIs creates a broad attack surface. Analysts observe that while critical backend systems remain resilient, user-facing applications and legacy components occasionally exhibit configuration weaknesses, requiring persistent patch management and vulnerability scanning to mitigate potential exploitation by threat actors targeting sensitive customer data and operational continuity.

CVE ID Title CVSS Severity Published
CVE-2026-104020 Uncontrolled recursion in the Ion reader in Amazon Ion Python — ion-python CWE-674 7.5 High 2026-10-01
CVE-2026-95985 Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces — Kiro IDE CWE-829 8.8 High 2026-09-24
CVE-2026-94384 Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda — amazon-connect-salesforce-lambda CWE-862 8.1 High 2026-09-22
CVE-2023-32803 Amazon ca-certificates 权限许可和访问控制问题漏洞 — ca-certificates CWE-669 7.5 High 2026-09-14
CVE-2026-85228 Integer overflow in tensor buffer validation in Deep Java Library — Deep Java Library CWE-190 9.1 Critical 2026-09-10
CVE-2026-85787 An incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-server — postgres-mcp-server CWE-184 6.5 Medium 2026-09-04
CVE-2026-85786 Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-java — ion-java CWE-409 7.5 High 2026-09-04
CVE-2026-85656 OS command injection in Amazon log4j-cve-2021-44228-hotpatch — log4j-cve-2021-44228-hotpatch CWE-78 7.8 High 2026-09-04
CVE-2026-85654 Code injection in the CDK generator in Amazon awslabs.dynamodb-mcp-server — awslabs.dynamodb-mcp-server CWE-1336 7.8 High 2026-09-04
CVE-2026-84851 Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6 — ion-c CWE-674 7.5 High 2026-09-02
CVE-2026-81849 Path traversal in the aws:downloadContent plugin in amazon-ssm-agent — amazon-ssm-agent CWE-23 8.8 High 2026-08-28
CVE-2026-78379 Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools — strands-agents-tools CWE-1427 8.1 High 2026-08-25
CVE-2026-18657 Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows — Kiro CLI CWE-427 7.8 High 2026-08-04
CVE-2026-18656 Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows — Kiro IDE CWE-427 7.8 High 2026-08-04
CVE-2026-16318 QUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tls — s2n-tls CWE-401 5.3 Medium 2026-07-21
CVE-2026-15746 Credential disclosure in Strands Agents Tools elasticsearch_memory tool — strands-agents-tools CWE-918 6.5 Medium 2026-07-15
CVE-2026-15738 Cross-namespace traffic interception via incorrect route precedence ordering in AWS Load Balancer Controller — aws-load-balancer-controller CWE-653 8.5 High 2026-07-14
CVE-2026-8178 Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver — Amazon Redshift JDBC Driver CWE-470 8.1 High 2026-05-08
CVE-2026-7791 Amazon WorkSpaces 安全漏洞 — Workspaces CWE-367 7.8 High 2026-05-04
CVE-2026-6437 AWS EFS CSI Driver Mount Option Injection — AWS EFS CSI Driver CWE-88 6.5 Medium 2026-04-17
CVE-2026-35558 Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver — Amazon Athena ODBC driver CWE-77 7.8 High 2026-04-03
CVE-2026-35559 Out-of-bounds write in query processing components in Amazon Athena ODBC driver — Amazon Athena ODBC driver CWE-787 6.5 Medium 2026-04-03
CVE-2026-5485 OS command injection in Amazon Athena ODBC driver on Linux — Amazon Athena ODBC driver CWE-78 7.8 High 2026-04-03
CVE-2026-35562 Allocation of resources without limits in parsing components in Amazon Athena ODBC driver — Amazon Athena ODBC driver CWE-770 7.5 High 2026-04-03
CVE-2026-35561 Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver — Amazon Athena ODBC driver CWE-862 7.4 High 2026-04-03
CVE-2026-35560 Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver — Amazon Athena ODBC driver CWE-295 7.4 High 2026-04-03
CVE-2025-12829 Amazon Ion C 安全漏洞 — Ion-C CWE-125 6.2 Medium 2025-11-07
CVE-2025-12779 Amazon WorkSpaces 安全漏洞 — Amazon WorkSpaces CWE-497 8.8 High 2025-11-05
CVE-2025-11573 Denial of Service issue in Amazon.IonDotnet — Amazon.IonDotnet CWE-1286 7.5 High 2025-10-09
CVE-2025-9039 Information Disclosure in Amazon ECS Container Agent — ECS CWE-277 4.3 Medium 2025-08-14

This page lists every published CVE security advisory associated with Amazon. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.