PatchSiren

AWS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH AWS CVE published 2026-08-06

CVE-2026-19111

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:16:55.410Z and has not been modified since then. The NVD entry is currently Received. CVE-2026-19111 is an insecure direct object reference vulnerability in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before version 0.8.3. The issue might allo [truncated]

MEDIUM AWS CVE published 2026-07-30

CVE-2026-18245

The CVE-2026-18245 vulnerability relates to improper control of code generation in Amazon Amplify Codegen Ui versions prior to 2.20.6. This issue might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values. Users of Amazon Amplify Codegen Ui should be a [truncated]

HIGH AWS CVE published 2026-07-21

CVE-2026-16317

CVE-2026-16317 is a validation issue in s2n-tls that allows an active man-in-the-middle to silently discard individual application data records without either endpoint detecting the modification. This issue affects all TLS 1.3 connections, impacting both TLS clients and servers. The vulnerability stems from the AEAD implementation hardcoding the outer content_type value in the additional authenticated dat [truncated]

HIGH AWS CVE published 2026-07-21

CVE-2026-15957

A high-severity vulnerability was found in Smithy-RS, a Rust code generation and runtime framework used for generating HTTP clients and servers from Smithy interface definitions. This issue is caused by uncontrolled recursion in JSON, CBOR, and XML deserializer functions, which could allow remote attackers to cause a denial of service via stack exhaustion. The vulnerability affects users of the AWS SDK fo [truncated]

MEDIUM AWS CVE published 2026-07-17

CVE-2026-15415

AWS HealthOmics is a HIPAA-eligible service managing infrastructure for bioinformatics analyses. A path traversal issue in the linting tools of the AWS HealthOmics MCP Server before version 0.0.36 might allow an actor to write content to arbitrary locations outside the intended workflow bundle directory. This issue has a CVSS score of 6.8 and a severity of MEDIUM. The vulnerability is caused by improper l [truncated]

MEDIUM AWS CVE published 2026-07-17

CVE-2026-12283

Amazon Athena Query Federation's Synapse connector has a SQL injection vulnerability due to improper neutralization of special elements used in SQL commands. This issue affects versions v2022.20.1 through v2026.19.1. An authenticated remote user could exploit this by crafting a table name to execute injected read-only SQL queries, potentially returning unintended data from the connected database. The CVSS [truncated]

MEDIUM AWS CVE published 2026-07-16

CVE-2026-15737

The AWS Bedrock AgentCore Python SDK, an open-source library for building AI agents on Amazon Bedrock AgentCore, had a vulnerability in versions 1.4.8 and 1.5.0. The OpenTelemetry instrumentation unintentionally logged sensitive user content, including raw user prompts and complete agent responses, without filtering or masking. These logs were written to span attributes and flowed into the customer's aws/ [truncated]

HIGH AWS CVE published 2026-07-07

CVE-2026-14904

CVE-2026-14904 is an improper link resolution before file access issue in AWS Research and Engineering Studio (RES). An authenticated remote user could read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key file with a symbolic link targeting any file on the host. This vulnerability allows access to any file readable by root, including other users' SSH private keys and [truncated]

HIGH AWS CVE published 2026-07-06

CVE-2026-14471

CVE-2026-14471 Improper Neutralization of Special Elements in metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute arbitrary SQL queries via a crafted table_name value that is interpolated into SQL statements in identifier position. This vulnerability has a high CVSS score of 8.6 and is considered a high prio [truncated]

HIGH AWS CVE published 2026-07-01

CVE-2026-14265

The CVE record for CVE-2026-14265 was published on 2026-07-01T20:17:08.087Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0, specifically the RemoteQueryCachePlugin, which uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey. This al [truncated]

HIGH AWS CVE published 2026-06-17

CVE-2026-12530

CVE-2026-12530 is an improper neutralization of argument delimiters vulnerability in the install_packages() method of AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1. This might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. Users of affected versions should be aware of this vulnerability and take steps [truncated]

MEDIUM AWS CVE published 2026-06-15

CVE-2026-11931

CVE-2026-11931 is a medium-severity vulnerability affecting Kiro IDE on macOS and Linux before version 0.11.133. The vulnerability is caused by incorrect default permissions, which expose the authentication token cache file to other local users or processes. The cache file has world-readable permissions (0644) instead of owner-restricted permissions (0600).

HIGH AWS CVE published 2026-06-10

CVE-2026-11417

CVE-2026-11417 is a HIGH-severity vulnerability in the NodejsFunction local bundling pipeline of aws-cdk-lib. An actor who controls the value of one or more bundling properties (externalModules, define, loader, inject, or esbuildArgs) might execute arbitrary commands on the host running the CDK toolchain via injected shell metacharacters. This requires the threat actor to control the value of one or more [truncated]

HIGH AWS CVE published 2026-06-08

CVE-2026-11393

CVE-2026-11393 is a HIGH severity vulnerability with a CVSS score of 8.8. The vulnerability is due to improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2. This could allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another u [truncated]

HIGH AWS CVE published 2026-06-05

CVE-2026-11401

CVE-2026-11401 is a HIGH severity vulnerability with a CVSS score of 8.6. An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL allows a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to [truncated]

HIGH AWS CVE published 2026-05-22

CVE-2026-9291

CVE-2026-9291 describes a vulnerability in the Amazon Braket SDK, specifically in the job results processing component. The issue is related to insecure deserialization, which might allow a remote authenticated user with S3 write access to the job output bucket to achieve arbitrary code execution on any machine that processes job results. The vulnerability has a CVSS score of 7.5 and is classified as HIGH [truncated]

HIGH AWS CVE published 2026-05-22

CVE-2026-9255

CVE-2026-9255 is a HIGH severity vulnerability in Kiro CLI versions prior to 1.28.0. The issue arises from missing input source validation in the tool authorization prompt, allowing a local attacker to execute arbitrary tools or shell commands without user approval by manipulating input piped to kiro-cli via stdin. The vulnerability has a CVSS score of 8.4.

HIGH AWS CVE published 2026-05-20

CVE-2026-9133

CVE-2026-9133 describes a high-severity flaw in the rabbitmq-aws component used with Amazon MQ. According to the CVE and NVD record, a debug ARN scheme was left active in the ARN resolver before version 0.2.1. If an authenticated user can reach the PUT /api/aws/arn/validate endpoint, the accepted arn:aws-debug:file scheme may allow arbitrary file reads from paths accessible to the RabbitMQ process. The pu [truncated]

CRITICAL AWS CVE published 2026-05-18

CVE-2026-8838

CVE-2026-8838 is a critical client-side code execution issue in amazon-redshift-python-driver before 2.1.14. The flaw stems from unsafe use of Python eval() on data received from the server in vector_in(), which means a rogue server or man-in-the-middle actor could potentially trigger arbitrary code execution on the client. AWS and the GitHub advisory both direct users to upgrade to version 2.1.14.

HIGH AWS CVE published 2026-04-06

CVE-2026-5709

CVE-2026-5709 is a high-severity vulnerability in AWS Research and Engineering Studio (RES). The issue arises from unsanitized input in the FileBrowser API, which could allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance. This vulnerability affects RES versions 2024.10 through 2025.12.01. Users are advised to upgrade to RES version 2026.03 or apply the corr [truncated]

HIGH AWS CVE published 2026-04-06

CVE-2026-5708

CVE-2026-5708 is a HIGH severity vulnerability in AWS Research and Engineering Studio (RES) prior to version 2026.03. The vulnerability involves unsanitized control of user-modifiable attributes in the session creation component, allowing an authenticated remote user to escalate privileges and interact with AWS resources and services. This type of vulnerability typically allows attackers to gain unauthori [truncated]

HIGH AWS CVE published 2026-04-06

CVE-2026-5707

CVE-2026-5707 is a high-severity vulnerability in AWS Research and Engineering Studio (RES) that allows remote authenticated actors to execute arbitrary OS commands as root on the virtual desktop host. The issue arises from unsanitized input in the virtual desktop session name handling. Affected versions include RES 2025.03 through 2025.12.01. Users are advised to upgrade to RES version 2026.03 or apply t [truncated]

HIGH AWS CVE published 2026-04-02

CVE-2026-5429

CVE-2026-5429 is a high-severity vulnerability in the Kiro Agent webview of Kiro IDE versions prior to 0.8.140. The issue arises from unsanitized input during web page generation, allowing a remote unauthenticated threat actor to execute arbitrary code via a crafted color theme name when a local user opens the workspace. This requires the user to trust the workspace when prompted. The vulnerability has a [truncated]

HIGH AWS CVE published 2026-03-31

CVE-2026-5190

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. This vulnerability has a high impact due to potential for arbitrary code execution. Users of aws-c-event-stream before version 0.6.0 should [truncated]

MEDIUM AWS CVE published 2026-03-16

CVE-2026-4270

CVE-2026-4270 is a medium-severity vulnerability in AWS API MCP Server where improper protection of an alternate path in the no-access and workdir feature can bypass intended file access restrictions. In affected versions, this may expose arbitrary local file contents in the MCP client application context. AWS and NVD both point users to version 1.3.9 as the remediation.

HIGH AWS CVE published 2026-03-02

CVE-2026-3338

CVE-2026-3338 is a HIGH-severity vulnerability in AWS-LC, a cryptographic library developed by Amazon. The vulnerability is caused by improper signature validation in the PKCS7_verify() function, which allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. This vulnerability was published on March 2, 2026, and last modified on June 30, [truncated]

HIGH AWS CVE published 2026-03-02

CVE-2026-3336

CVE-2026-3336 is a HIGH-severity vulnerability in AWS-LC, a cryptographic library developed by Amazon. The vulnerability is caused by improper certificate validation in the PKCS7_verify() function, which allows an unauthenticated attacker to bypass certificate chain verification when processing PKCS7 objects with multiple signers. However, customers of AWS services do not need to take action. Applications [truncated]