VulnSea

Amazon has 13 CVEs on record between 2024 and 2026. Cadence is steady at roughly 6 per quarter. The busiest recent month was April 2026 with 5. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-78 (3). Most affected products: research_and_engineering_studio (3), Deep Java Library (1), advanced_jdbc_wrapper (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
6 prev 5

Products

  • research_and_engineering_studio 3
  • Deep Java Library 1
  • advanced_jdbc_wrapper 1
  • athena_odbc 1
  • aws_amplify_cli 1
  • aws_encryption_sdk 1
13
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

Amazon vulnerabilities

CVEs affecting Amazon, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2023-32803High· 7.5
1w ago

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23…

TwilightAmazon · ca-certificatesEPSS 0.18%via NVD
CVE-2026-18061Medium· 5.9
1w ago

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files f…

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files f…

Sunlitamazon · advanced_jdbc_wrapperEPSS 0.27%via NVD
CVE-2026-89332Medium· 5.5
1w ago

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Craf…

Sunlitamazon · kiro_ideEPSS 0.17%via NVD
CVE-2026-85228Critical· 9.1
1w ago

Integer overflow in tensor buffer validation in Deep Java Library

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or …

MidnightAmazon · Deep Java LibraryEPSS 0.38%via CVEORG
CVE-2026-85787Medium· 6.5
2w ago

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL int…

An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL int…

SunlitAmazon · postgres-mcp-serverEPSS 0.20%via NVD
CVE-2026-11400High· 8.0
2mo ago

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Twilightamazon · software.amazon.jdbc:aws-advanced-jdbc-wrapperEPSS 0.30%via GHSA
CVE-2026-5747High· 7.5
5mo ago

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execut…

An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and aarch64 might allow a local guest user with root privileges to crash the Firecracker VMM process or potentially execut…

Twilightamazon · firecrackerEPSS 0.21%via NVD
CVE-2026-5709High· 8.8
5mo ago

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via craft…

Twilightamazon · research_and_engineering_studioEPSS 1.1%via NVD
CVE-2026-5708High· 8.8
5mo ago

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual…

Twilightamazon · research_and_engineering_studioEPSS 0.84%via NVD
CVE-2026-5707High· 8.8
5mo ago

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as roo…

Twilightamazon · research_and_engineering_studioEPSS 0.99%via NVD
CVE-2026-5485High· 7.8
5mo ago

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded…

OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded…

Twilightamazon · athena_odbcEPSS 0.73%via NVD
CVE-2024-28056Critical· 9.8
2y ago

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "…

Midnightamazon · aws_amplify_cliEPSS 1.7%via NVD
CVE-2024-23680Medium· 5.3
2y ago

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Sunlitamazon · aws_encryption_sdkEPSS 0.21%via NVD
Amazon vulnerabilities (CVEs) · VulnSea