Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

aws — Vulnerabilities & Security Advisories 151

Browse all 151 CVE security advisories affecting aws. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services operates as a comprehensive cloud computing platform, providing infrastructure, storage, and networking solutions to enterprises globally. With 68 recorded Common Vulnerabilities and Exposures, the platform’s security landscape reflects the complexity of its vast ecosystem. Historically, identified flaws have predominantly involved cross-site scripting, remote code execution, and privilege escalation issues, often stemming from misconfigurations or third-party component dependencies rather than core hypervisor failures. Notable incidents have occasionally highlighted risks associated with shared responsibility models, where customer-side errors led to data exposure. Despite these challenges, AWS maintains robust isolation mechanisms and continuous monitoring protocols. The frequency of vulnerabilities underscores the necessity for rigorous patch management and strict access controls. Users must remain vigilant, recognizing that while the underlying infrastructure is hardened, the security of deployed workloads largely depends on proper configuration and adherence to best practices within the shared responsibility framework.

CVE ID Title CVSS Severity Published
CVE-2026-106032 Server-side request forgery and local file read via unrestricted external OpenAPI reference resolution in Bedrock AgentCore Starter Toolkit agent import — bedrock-agentcore-starter-toolkit CWE-918 5.7 Medium 2026-10-06
CVE-2026-105812 Code injection via unencoded configuration values during Python code generation in Bedrock AgentCore Starter Toolkit agent import — bedrock-agentcore-starter-toolkit CWE-94 9.0 Critical 2026-10-06
CVE-2026-105811 Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS — qnabot-on-aws CWE-639 6.5 Medium 2026-10-06
CVE-2026-104019 OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio — sagemaker-distribution CWE-78 9.0 Critical 2026-10-02
CVE-2026-103958 Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS — loom CWE-918 7.6 High 2026-10-02
CVE-2026-103957 Server-side request forgery in the OAuth2 discovery handling in Loom for AWS — loom CWE-918 6.2 Medium 2026-10-02
CVE-2026-103956 Missing authentication for critical function in Loom for AWS — loom CWE-306 10.0 Critical 2026-10-02
CVE-2026-104002 Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python) — powertools-lambda-python CWE-390 5.3 Medium 2026-10-01
CVE-2026-97662 Argument injection in the diff scan operation in AWS security-agent-mcp-server allows arbitrary host file creation, overwrite, and truncation outside the intended workspace — security-agent-mcp-server CWE-88 8.2 High 2026-10-01
CVE-2026-103505 AWS EFS CSI Driver Mount Option Injection via mounttargetipmap — aws-efs-csi-driver CWE-88 6.5 Medium 2026-10-01
CVE-2026-100308 GluonTS arbitrary command execution during model deserialization — gluonts CWE-502 7.8 High 2026-09-29
CVE-2026-96883 Type confusion in AWS pgcollection allows remote code execution — pgcollection CWE-843 8.8 High 2026-09-24
CVE-2026-94450 Potential denial of service when configured to send Retry packets in s2n-quic — s2n-quic CWE-1284 7.5 High 2026-09-22
CVE-2026-92943 Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python — AWSIoTPythonSDK CWE-297 8.1 High 2026-09-17
CVE-2026-86831 Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS — aws-network-policy-agent CWE-1289 8.7 High 2026-09-16
CVE-2026-86830 Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center — iam-identity-center-team CWE-266 7.2 High 2026-09-14
CVE-2026-89332 Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration — Kiro IDE CWE-829 5.5 Medium 2026-09-11
CVE-2026-89090 Denial of service in the event stream header decoder in AWS SDK for Go v2 — AWS SDK for Go v2 CWE-248 5.9 Medium 2026-09-11
CVE-2026-18061 Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin — AWS Advanced JDBC Wrapper CWE-611 5.9 Medium 2026-09-11
CVE-2026-89066 OS command injection in the task synthesis component in projen — projen CWE-78 7.8 High 2026-09-11
CVE-2026-89065 Relative path traversal in the generated file manifest cleanup component in projen — projen CWE-23 7.1 High 2026-09-11
CVE-2026-89049 Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent — Amazon SSM Agent CWE-918 9.9 Critical 2026-09-10
CVE-2026-87913 Missing S3 bucket ownership verification in the AWS Security Agent MCP server — AWS Security Agent MCP server CWE-283 5.9 Medium 2026-09-10
CVE-2026-87912 Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops — AWS Security Agent plugin CWE-283 5.9 Medium 2026-09-10
CVE-2026-87911 Read-only enforcement bypass enabling operating system command execution in the SQL validation component of Amazon awslabs postgres-mcp-server — AWS Labs postgres MCP Server CWE-78 9.6 Critical 2026-09-09
CVE-2026-85788 Incomplete list of disallowed inputs in awslabs mysql-mcp-server — AWS Labs MySQL MCP Server CWE-184 5.5 Medium 2026-09-09
CVE-2026-84942 Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards — Amazon OpenSearch Service CWE-79 8.7 High 2026-09-08
CVE-2026-85781 Unverified access point ownership in Amazon EFS CSI Driver — aws-efs-csi-driver CWE-283 8.7 High 2026-09-04
CVE-2026-85028 Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit — aws-fpga CWE-379 7.8 High 2026-09-03
CVE-2026-85012 OS command injection in the Amazon CodeCatalyst blueprints SDK — @amazon-codecatalyst/blueprints.blueprint CWE-78 8.0 High 2026-09-03

This page lists every published CVE security advisory associated with aws. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.