Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. This vulnerability has a high impact due to potential for arbitrary code execution. Users of aws-c-event-stream before version 0.6.0 should [truncated]
CVE-2026-4270 is a medium-severity vulnerability in AWS API MCP Server where improper protection of an alternate path in the no-access and workdir feature can bypass intended file access restrictions. In affected versions, this may expose arbitrary local file contents in the MCP client application context. AWS and NVD both point users to version 1.3.9 as the remediation.
CVE-2026-3338 is a HIGH-severity vulnerability in AWS-LC, a cryptographic library developed by Amazon. The vulnerability is caused by improper signature validation in the PKCS7_verify() function, which allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. This vulnerability was published on March 2, 2026, and last modified on June 30, [truncated]
CVE-2026-3336 is a HIGH-severity vulnerability in AWS-LC, a cryptographic library developed by Amazon. The vulnerability is caused by improper certificate validation in the PKCS7_verify() function, which allows an unauthenticated attacker to bypass certificate chain verification when processing PKCS7 objects with multiple signers. However, customers of AWS services do not need to take action. Applications [truncated]