Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

aws — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting aws. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Amazon Web Services operates as a comprehensive cloud computing platform, providing infrastructure, storage, and networking solutions to enterprises globally. With 68 recorded Common Vulnerabilities and Exposures, the platform’s security landscape reflects the complexity of its vast ecosystem. Historically, identified flaws have predominantly involved cross-site scripting, remote code execution, and privilege escalation issues, often stemming from misconfigurations or third-party component dependencies rather than core hypervisor failures. Notable incidents have occasionally highlighted risks associated with shared responsibility models, where customer-side errors led to data exposure. Despite these challenges, AWS maintains robust isolation mechanisms and continuous monitoring protocols. The frequency of vulnerabilities underscores the necessity for rigorous patch management and strict access controls. Users must remain vigilant, recognizing that while the underlying infrastructure is hardened, the security of deployed workloads largely depends on proper configuration and adherence to best practices within the shared responsibility framework.

CVE ID Title CVSS Severity Published
CVE-2026-14904 RES Auth.GetUserPrivateKey Arbitrary File Read — res CWE-59 6.5 Medium 2026-07-07
CVE-2026-14471 Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry — MCP Gateway & Registry CWE-89 8.1 High 2026-07-06
CVE-2026-14265 RCE via Deserialization in AWS Advanced JDBC Wrapper — AWS Advanced JDBC Wrapper CWE-502 7.5 High 2026-07-01
CVE-2026-13760 OS Command Injection in aws-cdk-lib Docker Bundling — AWS CDK CWE-78 7.3 High 2026-07-01
CVE-2026-13769 Overly permissive File Permissions in AWS CLI — AWS CLI CWE-732 5.5 Medium 2026-07-01
CVE-2026-13763 HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF — AWS Application Load Balancer CWE-444 9.8 Critical 2026-06-29
CVE-2026-13762 HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF — Amazon CloudFront CWE-444 9.8 Critical 2026-06-29
CVE-2026-12530 Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() — bedrock-agentcore CWE-88 7.3 High 2026-06-17
CVE-2026-11931 Insecure Permissions on Authentication Token Cache File in Kiro IDE — Kiro IDE CWE-276 5.5 Medium 2026-06-15
CVE-2026-12043 Heap double-free in AWS Common Runtime aws-c-http — aws-c-http CWE-415 8.8 High 2026-06-12
CVE-2026-10740 Excessive memory allocation in s2n-quic — s2n-quic CWE-770 5.3 Medium 2026-06-10
CVE-2026-11417 OS Command Injection in NodejsFunction Bundling in aws-cdk-lib — AWS Cloud Development Kit library CWE-78 7.3 High 2026-06-10
CVE-2026-11393 Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import — AgentCore CLI CWE-94 9.0 Critical 2026-06-08
CVE-2026-11401 Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL — AWS Advanced Go Wrapper CWE-426 8.0 High 2026-06-05
CVE-2026-11400 Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL — AWS Advanced JDBC Wrapper CWE-426 8.0 High 2026-06-05
CVE-2026-10584 HTTPS Fallback to HTTP in Graph Explorer — Graph Explorer CWE-319 5.9 Medium 2026-06-02
CVE-2026-10591 Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths — Kiro IDE CWE-732 8.8 High 2026-06-02
CVE-2026-9291 Insecure Deserialization in Amazon Braket SDK Job Results Processing — Amazon Braket Python SDK CWE-502 7.1 High 2026-05-22
CVE-2026-9255 Tool Execution Without Authorization via Piped Stdin in Kiro CLI — Kiro CLI CWE-862 7.8 High 2026-05-22
CVE-2026-9133 Arbitrary file read in rabbitmq-aws plugin — RabbitMQ AWS CWE-489 7.7 High 2026-05-20
CVE-2026-8838 Remote Code Execution via eval() Injection in amazon-redshift-python-driver — Amazon Redshift connector for Python CWE-94 9.8 Critical 2026-05-18
CVE-2026-7461 OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials — Amazon ECS Agent CWE-78 7.2 High 2026-04-30
CVE-2026-7426 Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-787 8.1 High 2026-04-29
CVE-2026-7425 Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-125 6.5 Medium 2026-04-29
CVE-2026-7424 Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-191 8.1 High 2026-04-29
CVE-2026-7423 Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP — FreeRTOS-Plus-TCP CWE-191 5.3 Medium 2026-04-29
CVE-2026-7422 MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing — FreeRTOS-Plus-TCP CWE-290 6.5 Medium 2026-04-29
CVE-2026-7191 Arbitrary Code Execution via Sandbox Bypass in the open source solution QnABot on AWS — QnABot on AWS CWE-94 7.2 High 2026-04-27
CVE-2026-6968 Multiple Path Traversal Variants in awslabs/tough — tough CWE-22 5.9 Medium 2026-04-24
CVE-2026-6967 Missing Delegated Metadata Validation in awslabs/tough — tough CWE-345 5.9 Medium 2026-04-24

This page lists every published CVE security advisory associated with aws. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.