CVE-2026-11401High· 8.0▾ TwilightAWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
Aurora PostgreSQL is a fully managed relational database engine that's compatible with PostgreSQL.
An issue in Aurora PostgreSQL using the AWS Go Wrapper waa identified, see CVE-2026-11401.
Impact An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
Impacted versions: AWS Go Wrapper 2026-04-06
Patches This issue has been addressed in AWS Go Wrapper 2026-05-26. Maintainers recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds Remove the public schema from the search path.
References If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the vulnerability reporting page or directly via email to [email protected]. Please do not create a public GitHub issue.
github.com/aws/aws-advanced-go-wrapper/awssql/v2 <= 2.0.0github.com/aws/aws-advanced-go-wrapper/xray <= 1.06github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager <= 1.1.1github.com/aws/aws-advanced-go-wrapper/custom-endpoint <= 1.0.3github.com/aws/aws-advanced-go-wrapper/federated-auth <= 1.1.0github.com/aws/aws-advanced-go-wrapper/iam <= 1.1.0github.com/aws/aws-advanced-go-wrapper/mysql-driver <= 1.1.0github.com/aws/aws-advanced-go-wrapper/okta <= 1.1.0github.com/aws/aws-advanced-go-wrapper/pgx-driver <= 1.1.0github.com/aws/aws-advanced-go-wrapper/otlp <= 1.0.6github.com/aws/aws-advanced-go-wrapper/auth-helpers <= 1.1.0Upgrade to a patched release:
github.com/aws/aws-advanced-go-wrapper/awssql/v2 2.0.1github.com/aws/aws-advanced-go-wrapper/xray 1.07github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager 1.1.2github.com/aws/aws-advanced-go-wrapper/custom-endpoint 1.0.4github.com/aws/aws-advanced-go-wrapper/federated-auth 1.1.1github.com/aws/aws-advanced-go-wrapper/iam 1.1.1github.com/aws/aws-advanced-go-wrapper/mysql-driver 1.1.1github.com/aws/aws-advanced-go-wrapper/okta 1.1.1github.com/aws/aws-advanced-go-wrapper/pgx-driver 1.1.1github.com/aws/aws-advanced-go-wrapper/otlp 1.0.7github.com/aws/aws-advanced-go-wrapper/auth-helpers 1.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
GO-2026-6093NoneAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
CVE-2026-11400High· 8.0AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream