PatchSiren cyber security CVE debrief
CVE-2026-35562 Amazon CVE debrief
The CVE-2026-35562 vulnerability is related to the Amazon Athena ODBC driver before version 2.1.0.0. This vulnerability might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7, indicating a high severity level. The vulnerability is categorized under CWE-770, which relates to allocation of resources without limits. Users should upgrade to version 2.1.0.0 to remediate this issue. The NVD entry is currently Analyzed, and the CVE record was published on 2026-04-03T21:17:12.427Z.
- Vendor
- Amazon
- Product
- Amazon Athena ODBC driver
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-03
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-03
- Advisory updated
- 2026-07-24
Who should care
Users of Amazon Athena ODBC driver versions prior to 2.1.0.0, especially those with deployments in managed environments, should be aware of this vulnerability and take necessary actions to upgrade to the latest version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess and mitigate potential impacts.
Technical summary
The Amazon Athena ODBC driver before version 2.1.0.0 has a vulnerability that could lead to a denial of service due to excessive resource consumption triggered by crafted input. This issue arises from the allocation of resources without limits in the parsing components of the driver. The vulnerability has a CVSS score of 8.7 and is classified under CWE-770. Users of the affected driver versions should review their deployments, validate input, and consider upgrading to version 2.1.0.0 or later.
Defensive priority
High
Recommended defensive actions
- Upgrade to Amazon Athena ODBC driver version 2.1.0.0 or later
- Review and limit input to the ODBC driver to prevent crafted input
- Monitor system resources for unusual consumption patterns
- Implement compensating controls to detect and respond to potential denial of service attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-03T21:17:12.427Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The Amazon Athena ODBC driver before version 2.1.0.0 has a vulnerability that could lead to a denial of service due to excessive resource consumption triggered by crafted input. Users should verify their deployments and review official advisories for affected scope and severity. Defenders should focus on validating input and monitoring for unusual consumption patterns.
Official resources
-
CVE-2026-35562 CVE record
CVE.org
-
CVE-2026-35562 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch
-
Mitigation or vendor reference
ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T21:17:12.427Z and has not been modified since then. The NVD entry is currently Analyzed.