CVE-2022-2582Medium· 4.3▾ SunlitAWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
The AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field. This hash can be used to brute force the plaintext, if the hash is readable to the attacker. AWS now blocks this metadata field, but older SDK versions still send it.
github.com/aws/aws-sdk-go < 1.34.0Upgrade to a patched release:
github.com/aws/aws-sdk-go 1.34.0Connected by shared product, vendor, weakness, or advisory.
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
GO-2026-6093NoneAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
GHSA-xmrv-pmrh-hhx2Medium· 5.9Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
CVE-2026-7461High· 7.2Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure