GHSA-xmrv-pmrh-hhx2Medium· 5.9▾ SunlitDenial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
CVSSv3.1 Rating: [Medium] CVSSv3.1 Score: [5.9] CVSSv3.1 Vector String: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H]
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate.
Impacted versions: < 2026-03-23
This issue has been addressed in versions 2026-03-23 and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Not Applicable
If you have any questions or comments about this advisory, we ask that you contact [AWS/Amazon] Security via our vulnerability reporting page or directly via email to [email protected]. Please do not create a public GitHub issue.
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream < 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore < 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime < 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime < 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs < 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise < 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis < 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda < 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 < 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 < 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime < 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming < 1.34.5Upgrade to a patched release:
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming 1.34.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
GO-2026-6093NoneAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
CVE-2026-7461High· 7.2Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure