Junglewise Threat Intelligence

CVE-2026-5190: AWS aws-c-event-stream out-of-bounds write in streaming decoder

CVE-2026-5190 · Severity: high · CVSS 7.5 · Published 2026-03-31

Technologies: Amazon AWS. Vendors: Amazon Web Services, AWS, Amazon.

Executive brief

A security vulnerability exists in a core AWS library used by various software development kits (SDKs) to handle streaming data. If a client application connects to a malicious or compromised server, that server could send specially crafted messages to take control of the client application or cause it to crash. This could lead to unauthorized data access or a complete disruption of the application's operations.

Technical details

An out-of-bounds write (specifically a stack buffer overflow) exists in the streaming decoder component of the aws-c-event-stream library during the parsing of headers. The vulnerability is triggered when a client application processes a maliciously crafted event-stream message from a server it is connected to. While the attack requires the client to connect to a non-trusted third-party server (high attack complexity/requirements), a successful exploit allows for memory corruption and arbitrary code execution on the client system. The issue affects the core C library and several higher-level AWS SDKs (C++, Java, Python, JS, Swift) that wrap this functionality. Fixes are available in aws-c-event-stream version 0.6.0 and corresponding SDK updates.

Affected products

  • AWS aws-c-event-stream < 0.6.0
  • AWS aws-iot-device-sdk-cpp-v2 < 1.42.1
  • AWS aws-iot-device-sdk-java-v2 < 1.30.1
  • AWS aws-iot-device-sdk-python-v2 < 1.28.2
  • AWS aws-iot-device-sdk-js-v2 < 1.25.1
  • AWS aws-sdk-swift < 1.6.70
  • AWS aws-sdk-cpp < 1.11.764

Timeline

  • 2026-03-31: advisory: Initial advisory published by AWS and GitHub Security Advisory created.
  • 2026-03-31: patched: Version 0.6.0 released to address the overflow.

References

Related threats