CVE-2026-89090Medium· 5.9▾ SunlitAn unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.
To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream < 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore < 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime < 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime < 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs < 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise < 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis < 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda < 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 < 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 < 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime < 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming < 1.34.5Patched in:
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming 1.34.5Source: https://osv.dev/vulnerability/GHSA-xmrv-pmrh-hhx2
Connected by shared product, vendor, weakness, or advisory.
GHSA-xmrv-pmrh-hhx2Medium· 5.9Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
CVE-2026-88015Medium· 5.3rclone is a command-line program to sync files and directories to and from different cloud storage providers
CVE-2026-84445High· 8.7gRPC-Go is the Go language implementation of gRPC
CVE-2026-92081Medium· 5.9fastify is a fast and low-overhead web framework for Node.js
CVE-2026-2229High· 7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension