GO-2026-5764None▾ SunlitDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream < 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore < 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime < 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime < 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs < 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise < 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis < 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda < 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 < 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 < 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime < 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming < 1.34.5Upgrade to a patched release:
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream 1.7.8github.com/aws/aws-sdk-go-v2/service/bedrockagentcore 1.15.2github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime 1.51.8github.com/aws/aws-sdk-go-v2/service/bedrockruntime 1.50.4github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs 1.65.0github.com/aws/aws-sdk-go-v2/service/iotsitewise 1.52.19github.com/aws/aws-sdk-go-v2/service/kinesis 1.43.5github.com/aws/aws-sdk-go-v2/service/lambda 1.88.5github.com/aws/aws-sdk-go-v2/service/lexruntimev2 1.35.15github.com/aws/aws-sdk-go-v2/service/s3 1.97.3github.com/aws/aws-sdk-go-v2/service/sagemakerruntime 1.39.6github.com/aws/aws-sdk-go-v2/service/transcribestreaming 1.34.5Connected by shared product, vendor, weakness, or advisory.
GHSA-xmrv-pmrh-hhx2Medium· 5.9Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
GO-2026-6093NoneAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
CVE-2026-7461High· 7.2Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure