GO-2026-6093None▾ SunlitAWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk
github.com/aws/aws-cdk-go/awscdk >= 1.175.0-devpreviewgithub.com/aws/aws-cdk-go/awscdk/v2 < 2.253.0Upgrade to a patched release:
github.com/aws/aws-cdk-go/awscdk/v2 2.253.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89090Medium· 5.9An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …
CVE-2020-8912Low· 2.5In-band key negotiation issue in AWS S3 Crypto SDK for golang
CVE-2022-2582Medium· 4.3AWS S3 Crypto SDK sends an unencrypted hash of the plaintext alongside the ciphertext as a metadata field
GO-2026-5764NoneDoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
GHSA-xmrv-pmrh-hhx2Medium· 5.9Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
CVE-2026-7461High· 7.2Amazon ECS Container Agent (Windows) is vulnerable to Information Disclosure