Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

aws — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting aws. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services operates as a comprehensive cloud computing platform, providing infrastructure, storage, and networking solutions to enterprises globally. With 68 recorded Common Vulnerabilities and Exposures, the platform’s security landscape reflects the complexity of its vast ecosystem. Historically, identified flaws have predominantly involved cross-site scripting, remote code execution, and privilege escalation issues, often stemming from misconfigurations or third-party component dependencies rather than core hypervisor failures. Notable incidents have occasionally highlighted risks associated with shared responsibility models, where customer-side errors led to data exposure. Despite these challenges, AWS maintains robust isolation mechanisms and continuous monitoring protocols. The frequency of vulnerabilities underscores the necessity for rigorous patch management and strict access controls. Users must remain vigilant, recognizing that while the underlying infrastructure is hardened, the security of deployed workloads largely depends on proper configuration and adherence to best practices within the shared responsibility framework.

CVE ID Title CVSS Severity Published
CVE-2026-77811 Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards — Amazon OpenSearch Service CWE-79 8.7 High 2026-08-21
CVE-2026-77810 Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector — Athena Federated Query Neptune Connector CWE-95 9.9 Critical 2026-08-21
CVE-2026-18420 RCE via Prototype Pollution in OpenSearch Dashboards — Amazon OpenSearch Service CWE-1321 8.8 High 2026-08-20
CVE-2026-75910 Incorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment template — Athena Federated Query Clickhouse Connector deployment template CWE-266 6.5 Medium 2026-08-20
CVE-2026-18428 SQL Query Validation Bypass in OpenSearch Direct Query — Opensearch CWE-693 8.8 High 2026-08-13
CVE-2026-19643 Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms — aws-sdk-cpp CWE-125 5.3 Medium 2026-08-12
CVE-2026-19642 Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp — aws-sdk-cpp CWE-787 5.9 Medium 2026-08-12
CVE-2026-18952 Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin — Opensearch CWE-918 8.1 High 2026-08-12
CVE-2026-19311 Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin — OpenSearch CWE-475 8.1 High 2026-08-12
CVE-2026-19111 Insecure direct object reference in Strands Agents Tools memory tool namespace isolation — strands-agents-tools CWE-639 8.1 High 2026-08-06
CVE-2026-18954 Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server — documentdb-mcp-server CWE-863 5.5 Medium 2026-08-05
CVE-2026-18953 Improper limitation of a pathname to a restricted directory in aws-transform-mcp-server — aws-transform-mcp-server CWE-22 8.6 High 2026-08-05
CVE-2026-18830 Insufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness API — Amazon Bedrock AgentCore harness CWE-1287 8.1 High 2026-08-04
CVE-2026-18733 Prompt injection bypasses shell tool consent gate in Strands Agents Tools — strands-agents-tools CWE-1427 8.8 High 2026-08-03
CVE-2026-18654 Disabled SSH host key verification in Amazon AWS CLI EMR helper commands — aws-cli CWE-322 6.8 Medium 2026-08-03
CVE-2026-18655 Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection — amazon-mq-mcp-server CWE-923 6.5 Medium 2026-08-03
CVE-2026-18394 Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration — Strands Agents Tools CWE-863 7.4 High 2026-07-31
CVE-2026-18481 Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft — AWS Ops Wheel CWE-79 7.3 High 2026-07-31
CVE-2026-18140 Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers — aws-smithy-json CWE-674 7.5 High 2026-07-30
CVE-2026-18245 Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react — Amplify Codegen UI CWE-94 9.0 Critical 2026-07-30
CVE-2026-16796 Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() — bedrock-agentcore 1.18.1 CWE-88 7.3 High 2026-07-23
CVE-2026-16756 Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service — aws-smithy-http-server CWE-770 7.5 High 2026-07-23
CVE-2026-16584 AWS API MCP Server Security Policy Bypass via Startup Failure — aws-api-mcp-server CWE-455 7.0 High 2026-07-23
CVE-2026-16317 Silent Drop of TLS 1.3 Encrypted Records in s2n-tls — s2n-tls CWE-354 6.5 Medium 2026-07-21
CVE-2026-15957 Uncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapes — aws-sdk-rust CWE-770 7.5 High 2026-07-21
CVE-2026-15415 Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server — aws-healthomics-mcp-server CWE-23 5.5 Medium 2026-07-17
CVE-2026-12283 SQL injection in Amazon Athena Synapse connector — aws-athena-query-federation CWE-89 6.8 Medium 2026-07-17
CVE-2026-15737 Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK — bedrock-agentcore CWE-532 5.7 Medium 2026-07-16
CVE-2026-15895 OS command injection in jsii-diff in AWS jsii — jsii CWE-78 7.8 High 2026-07-15
CVE-2026-15643 AWS HealthLake MCP Server SSRF via Pagination URL — awslabs.healthlake-mcp-server CWE-918 7.3 High 2026-07-14

This page lists every published CVE security advisory associated with aws. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.