PatchSiren

Amazon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Amazon CVE published 2026-08-04

CVE-2026-18656

An executive overview of CVE-2026-18656: This vulnerability affects Kiro IDE on Windows systems, specifically versions before 1.0.228. It is classified as an uncontrolled search path element, which could allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory. The vulnerability has a high CVSS score of 8.5, indicating a significant potential impact. Users [truncated]

HIGH Amazon CVE published 2026-07-30

CVE-2026-18140

The CVE-2026-18140 record indicates uncontrolled recursion in the aws-smithy-json runtime crate before 0.62.7, potentially allowing remote unauthenticated users to cause a denial of service via deeply nested JSON in a small HTTP request. This issue affects smithy-rs generated servers. Users should upgrade to aws-smithy-json 0.62.7 or later and rebuild. The vulnerability has a HIGH CVSS score of 8.7, empha [truncated]

MEDIUM Amazon CVE published 2026-07-21

CVE-2026-16318

The s2n-tls QUIC transport parameters extension handler incorrectly uses s2n_alloc instead of s2n_realloc to store peer's transport parameters. This can cause a memory leak during normal QUIC traffic when a client offers a key share group the server does not prefer. An unauthenticated user can amplify the issue by deliberately forcing HelloRetryRequests, causing up to approximately 64 KB of unreachable me [truncated]

MEDIUM Amazon CVE published 2026-04-17

CVE-2026-6437

A vulnerability in the AWS EFS CSI Driver before v3.0.1 allows remote authenticated users with PersistentVolume creation permissions to inject arbitrary mount options via comma injection in the volume handling component. The issue stems from improper neutralization of argument delimiters (CWE-88), which could lead to integrity impacts on the system cluster. The vulnerability was published on April 17, 202 [truncated]

HIGH Amazon CVE published 2026-04-08

CVE-2026-5747

An out-of-bounds write vulnerability in the virtio PCI transport of Amazon Firecracker allows a local guest user with root privileges to crash the VMM process or potentially execute arbitrary code on the host. The flaw exists in Firecracker versions 1.13.0 through 1.14.3 and version 1.15.0 on both x86_64 and aarch64 architectures. The vulnerability is triggered by modification of virtio queue configuratio [truncated]

HIGH Amazon CVE published 2026-04-03

CVE-2026-5485

A vulnerability in the Amazon Athena ODBC driver before version 2.0.5.1 on Linux allows for OS command injection through specially crafted connection parameters. This issue can be exploited by a threat actor to execute arbitrary code during a local user-initiated connection. The vulnerability has a CVSS score of 7.3 and is classified as HIGH severity. Users are advised to upgrade to version 2.0.5.1 or lat [truncated]

HIGH Amazon CVE published 2026-04-03

CVE-2026-35562

The CVE-2026-35562 vulnerability is related to the Amazon Athena ODBC driver before version 2.1.0.0. This vulnerability might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7, indicating a high severity level. T [truncated]

CRITICAL Amazon CVE published 2026-04-03

CVE-2026-35561

Amazon Athena ODBC driver versions before 2.1.0.0 contain insufficient authentication security controls in browser-based authentication components. This may allow threat actors to intercept or hijack authentication sessions due to insufficient protections in browser-based authentication flows. The vulnerability has a CVSS score of 9.1 and is classified as CRITICAL. Users should upgrade to version 2.1.0.0 [truncated]

CRITICAL Amazon CVE published 2026-04-03

CVE-2026-35560

The Amazon Athena ODBC driver before version 2.1.0.0 has a critical vulnerability CVE-2026-35560 due to improper certificate validation in its identity provider connection components. This issue might allow a man-in-the-middle threat actor to intercept authentication credentials when connecting to external identity providers. The vulnerability has a CVSS score of 9.1 and is considered critical. Organizati [truncated]

HIGH Amazon CVE published 2026-04-03

CVE-2026-35559

The CVE record for CVE-2026-35559 was published on 2026-04-03T21:17:11.900Z and has not been modified since then. The NVD entry is currently Analyzed. This out-of-bounds write vulnerability in the Amazon Athena ODBC driver before version 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data during query operations. Users of Amazon Athena ODBC driver versions before 2.1.0.0 [truncated]

HIGH Amazon CVE published 2026-04-03

CVE-2026-35558

The Amazon Athena ODBC driver before version 2.1.0.0 has a vulnerability that might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters. This issue arises from improper neutralization of special elements in the driver's authentication components. Users should upgrade to version 2.1.0.0 to remediate this issue. The vulnerability h [truncated]

MEDIUM Amazon CVE published 2026-03-16

CVE-2026-4269

CVE-2026-4269 is a build-time code injection issue in the AWS Bedrock AgentCore Starter Toolkit. According to the vendor and NVD, a missing S3 ownership verification before v0.1.13 can let a remote actor inject code during the build process, which may then lead to code execution in the AgentCore Runtime. The issue is limited to users of toolkit versions earlier than v0.1.13 who built, or still have build [truncated]