PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35562 Amazon CVE debrief

The CVE-2026-35562 vulnerability is related to the Amazon Athena ODBC driver before version 2.1.0.0. This vulnerability might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7, indicating a high severity level. The vulnerability is categorized under CWE-770, which relates to allocation of resources without limits. Users should upgrade to version 2.1.0.0 to remediate this issue. The NVD entry is currently Analyzed, and the CVE record was published on 2026-04-03T21:17:12.427Z.

Vendor
Amazon
Product
Amazon Athena ODBC driver
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-03
Original CVE updated
2026-07-24
Advisory published
2026-04-03
Advisory updated
2026-07-24

Who should care

Users of Amazon Athena ODBC driver versions prior to 2.1.0.0, especially those with deployments in managed environments, should be aware of this vulnerability and take necessary actions to upgrade to the latest version. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess and mitigate potential impacts.

Technical summary

The Amazon Athena ODBC driver before version 2.1.0.0 has a vulnerability that could lead to a denial of service due to excessive resource consumption triggered by crafted input. This issue arises from the allocation of resources without limits in the parsing components of the driver. The vulnerability has a CVSS score of 8.7 and is classified under CWE-770. Users of the affected driver versions should review their deployments, validate input, and consider upgrading to version 2.1.0.0 or later.

Defensive priority

High

Recommended defensive actions

  • Upgrade to Amazon Athena ODBC driver version 2.1.0.0 or later
  • Review and limit input to the ODBC driver to prevent crafted input
  • Monitor system resources for unusual consumption patterns
  • Implement compensating controls to detect and respond to potential denial of service attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-03T21:17:12.427Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The Amazon Athena ODBC driver before version 2.1.0.0 has a vulnerability that could lead to a denial of service due to excessive resource consumption triggered by crafted input. Users should verify their deployments and review official advisories for affected scope and severity. Defenders should focus on validating input and monitoring for unusual consumption patterns.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-35562 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-35562

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-35562 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35562

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://aws.amazon.com/security/security-bulletins/2026-013-aws/

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Vendor Advisory

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Release Notes

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi

    ff89ba41-3aa1-4d27-914a-91399e9639e5 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.