{"schema_version":1,"title":"AWS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 62 vulnerabilities in AWS: 1 in the last 7 days and 24 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-96883, was published on 24 September 2026. 4 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/aws","json_url":"https://junglewise.ai/threats/vendors/aws.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/aws","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":40,"all_time":62,"critical":4,"exploited":0,"last_7_days":1,"last_30_days":6,"last_90_days":24,"last_365_days":51},"latest":[{"cve":"CVE-2026-96883","cvss":8.8,"epss":0.0065,"slug":"cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution","title":"pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authen","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:35.24+00:00","url":"https://junglewise.ai/threats/cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution"},{"cve":"CVE-2026-86830","cvss":7.2,"epss":0.0069,"slug":"cve-2026-86830-aws-team-privilege-escalation-in-iam-identity-center","title":"Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 migh","severity":"high","exploited":false,"published_at":"2026-09-14T19:17:52.523+00:00","url":"https://junglewise.ai/threats/cve-2026-86830-aws-team-privilege-escalation-in-iam-identity-center"},{"cve":"CVE-2026-89332","cvss":5.5,"epss":0.0018,"slug":"cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written","title":"Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow","severity":"high","exploited":false,"published_at":"2026-09-11T20:19:23.67+00:00","url":"https://junglewise.ai/threats/cve-2026-89332-kiro-ide-sensitive-workspace-data-exfiltration-via-agent-written"},{"cve":"CVE-2026-85228","cvss":9.1,"epss":0.0054,"slug":"cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer","title":"An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms","severity":"critical","exploited":false,"published_at":"2026-09-10T17:17:06.437+00:00","url":"https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer"},{"cve":"CVE-2026-87912","cvss":5.9,"epss":0.0044,"slug":"cve-2026-87912-aws-security-agent-missing-s3-bucket-ownership-verification","title":"A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remo","severity":"high","exploited":false,"published_at":"2026-09-10T16:18:07.037+00:00","url":"https://junglewise.ai/threats/cve-2026-87912-aws-security-agent-missing-s3-bucket-ownership-verification"},{"cve":"CVE-2026-19311","cvss":0,"slug":"cve-2026-19311-opensearch-alerting-plugin-missing-authorization","title":"OpenSearch Alerting Plugin missing authorization","severity":"high","exploited":false,"published_at":"2026-09-09T21:35:24+00:00","url":"https://junglewise.ai/threats/cve-2026-19311-opensearch-alerting-plugin-missing-authorization"},{"cve":"CVE-2026-18656","cvss":7.8,"epss":0.0022,"slug":"cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory","title":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbi","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:50.41+00:00","url":"https://junglewise.ai/threats/cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory"},{"cve":"CVE-2026-18654","cvss":6.8,"epss":0.0029,"slug":"cve-2026-18654-aws-aws-cli-disabled-ssh-host-key-verification-in-emr-helper","title":"Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 migh","severity":"high","exploited":false,"published_at":"2026-08-03T20:17:17.383+00:00","url":"https://junglewise.ai/threats/cve-2026-18654-aws-aws-cli-disabled-ssh-host-key-verification-in-emr-helper"},{"cve":"CVE-2025-4318","cvss":4,"epss":0.0094,"slug":"cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui","title":"AWS Amplify Studio eval injection in amplify-codegen-ui","severity":"critical","exploited":false,"published_at":"2026-07-30T20:57:24+00:00","url":"https://junglewise.ai/threats/cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui"},{"cve":"CVE-2026-18140","cvss":7.5,"slug":"cve-2026-18140-aws-aws-smithy-json-denial-of-service-via-uncontrolled-recursion","title":"AWS aws-smithy-json denial of service via uncontrolled recursion","severity":"high","exploited":false,"published_at":"2026-07-30T19:17:26.457+00:00","url":"https://junglewise.ai/threats/cve-2026-18140-aws-aws-smithy-json-denial-of-service-via-uncontrolled-recursion"},{"cvss":3.1,"slug":"aws-cdk-codebuild-s3-log-encryption-boolean-inversion-53ea58e5","title":"AWS CDK CodeBuild S3 log encryption boolean inversion","severity":"low","exploited":false,"published_at":"2026-07-24T16:44:20+00:00","url":"https://junglewise.ai/threats/aws-cdk-codebuild-s3-log-encryption-boolean-inversion-53ea58e5"},{"cvss":3.3,"slug":"aws-cdk-boolean-inversion-in-codebuild-s3loggingoptions-8f423b83","title":"AWS CDK boolean inversion in CodeBuild S3LoggingOptions","severity":"low","exploited":false,"published_at":"2026-07-24T16:44:20+00:00","url":"https://junglewise.ai/threats/aws-cdk-boolean-inversion-in-codebuild-s3loggingoptions-8f423b83"},{"cve":"CVE-2026-16796","cvss":7.3,"epss":0.0073,"slug":"cve-2026-16796-aws-bedrock-agentcore-sdk-argument-injection-in-install-packages","title":"AWS Bedrock AgentCore SDK argument injection in install_packages","severity":"high","exploited":false,"published_at":"2026-07-23T21:17:03.51+00:00","url":"https://junglewise.ai/threats/cve-2026-16796-aws-bedrock-agentcore-sdk-argument-injection-in-install-packages"},{"cve":"CVE-2026-16756","cvss":7.5,"epss":0.0042,"slug":"cve-2026-16756-amazon-aws-smithy-http-server-denial-of-service-in-serve-path","title":"Amazon aws-smithy-http-server denial of service in serve path","severity":"high","exploited":false,"published_at":"2026-07-23T19:16:53.657+00:00","url":"https://junglewise.ai/threats/cve-2026-16756-amazon-aws-smithy-http-server-denial-of-service-in-serve-path"},{"cve":"CVE-2026-16584","cvss":7,"epss":0.0023,"slug":"cve-2026-16584-aws-aws-api-mcp-server-security-policy-bypass-via-initialization","title":"AWS AWS API MCP Server security policy bypass via initialization failure","severity":"high","exploited":false,"published_at":"2026-07-23T16:17:15.787+00:00","url":"https://junglewise.ai/threats/cve-2026-16584-aws-aws-api-mcp-server-security-policy-bypass-via-initialization"},{"cve":"CVE-2026-16317","cvss":6.5,"slug":"cve-2026-16317-aws-s2n-tls-silent-record-drop-in-tls-1-3","title":"AWS s2n-tls silent record drop in TLS 1.3","severity":"high","exploited":false,"published_at":"2026-07-21T21:16:49.06+00:00","url":"https://junglewise.ai/threats/cve-2026-16317-aws-s2n-tls-silent-record-drop-in-tls-1-3"},{"cve":"CVE-2026-15957","cvss":7.5,"slug":"cve-2026-15957-aws-smithy-rs-uncontrolled-recursion-in-deserializers","title":"AWS smithy-rs uncontrolled recursion in deserializers","severity":"high","exploited":false,"published_at":"2026-07-21T20:16:58.78+00:00","url":"https://junglewise.ai/threats/cve-2026-15957-aws-smithy-rs-uncontrolled-recursion-in-deserializers"},{"cve":"CVE-2026-15415","cvss":5.5,"slug":"cve-2026-15415-aws-healthomics-mcp-server-directory-traversal-in-workflow","title":"AWS HealthOmics MCP Server directory traversal in workflow linters","severity":"high","exploited":false,"published_at":"2026-07-17T20:17:15.923+00:00","url":"https://junglewise.ai/threats/cve-2026-15415-aws-healthomics-mcp-server-directory-traversal-in-workflow"},{"cve":"CVE-2026-12283","cvss":6.8,"slug":"cve-2026-12283-aws-athena-query-federation-sql-injection-in-synapse-connector","title":"AWS Athena Query Federation SQL injection in Synapse connector","severity":"high","exploited":false,"published_at":"2026-07-17T20:17:14.007+00:00","url":"https://junglewise.ai/threats/cve-2026-12283-aws-athena-query-federation-sql-injection-in-synapse-connector"},{"cve":"CVE-2026-15643","cvss":7.3,"slug":"cve-2026-15643-aws-healthlake-mcp-server-ssrf-in-pagination-handling","title":"AWS HealthLake MCP Server SSRF in pagination handling","severity":"high","exploited":false,"published_at":"2026-07-14T21:16:41.293+00:00","url":"https://junglewise.ai/threats/cve-2026-15643-aws-healthlake-mcp-server-ssrf-in-pagination-handling"},{"cve":"CVE-2025-12967","cvss":3.1,"epss":0.0045,"slug":"cve-2025-12967-aws-aurora-postgresql-privilege-escalation-in-multiple-sdk","title":"PYSEC-2026-1205 - AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance","severity":"high","exploited":false,"published_at":"2026-07-07T16:03:10.351969+00:00","url":"https://junglewise.ai/threats/cve-2025-12967-aws-aurora-postgresql-privilege-escalation-in-multiple-sdk"},{"cve":"CVE-2026-13760","cvss":7.3,"epss":0.0116,"slug":"cve-2026-13760-aws-aws-cdk-lib-os-command-injection-in-nodejsfunction-docker","title":"AWS aws-cdk-lib OS command injection in NodejsFunction Docker bundling","severity":"high","exploited":false,"published_at":"2026-07-01T19:16:36.157+00:00","url":"https://junglewise.ai/threats/cve-2026-13760-aws-aws-cdk-lib-os-command-injection-in-nodejsfunction-docker"},{"cve":"CVE-2026-49473","cvss":8.8,"epss":0.0047,"slug":"cve-2026-49473-aws-cedar-policy-express-js-middleware-authorization-bypass-via","title":"AWS Cedar Policy Express.js middleware authorization bypass via query string manipulation","severity":"high","exploited":false,"published_at":"2026-06-30T18:09:13+00:00","url":"https://junglewise.ai/threats/cve-2026-49473-aws-cedar-policy-express-js-middleware-authorization-bypass-via"},{"cve":"CVE-2026-13763","cvss":9.8,"slug":"cve-2026-13763-aws-application-load-balancer-waf-bypass-via-http-2-multi-frame","title":"AWS Application Load Balancer WAF bypass via HTTP/2 multi-frame requests","severity":"critical","exploited":false,"published_at":"2026-06-29T20:17:33.283+00:00","url":"https://junglewise.ai/threats/cve-2026-13763-aws-application-load-balancer-waf-bypass-via-http-2-multi-frame"},{"cve":"CVE-2026-12957","cvss":7.8,"epss":0.0018,"slug":"cve-2026-12957-aws-language-servers-arbitrary-code-execution-in-trusted","title":"AWS Language Servers arbitrary code execution in trusted workspaces","severity":"high","exploited":false,"published_at":"2026-06-23T17:16:40.977+00:00","url":"https://junglewise.ai/threats/cve-2026-12957-aws-language-servers-arbitrary-code-execution-in-trusted"}],"vendor":{"hub":true,"name":"AWS","slug":"aws","homepage":"https://aws.amazon.com/","description":"Amazon Web Services provides cloud computing infrastructure and platform services.","url":"https://junglewise.ai/threats/vendors/aws"},"weekly":[{"week":"2026-06-29","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-27","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":1}],"most_severe":[{"cve":"CVE-2026-13763","cvss":9.8,"slug":"cve-2026-13763-aws-application-load-balancer-waf-bypass-via-http-2-multi-frame","title":"AWS Application Load Balancer WAF bypass via HTTP/2 multi-frame requests","severity":"critical","exploited":false,"published_at":"2026-06-29T20:17:33.283+00:00","url":"https://junglewise.ai/threats/cve-2026-13763-aws-application-load-balancer-waf-bypass-via-http-2-multi-frame"},{"cve":"CVE-2026-85228","cvss":9.1,"epss":0.0054,"slug":"cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer","title":"An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms","severity":"critical","exploited":false,"published_at":"2026-09-10T17:17:06.437+00:00","url":"https://junglewise.ai/threats/cve-2026-85228-aws-deep-java-library-integer-overflow-in-tensor-buffer"},{"cve":"CVE-2026-11393","cvss":9,"epss":0.0034,"slug":"cve-2026-11393-aws-agentcore-cli-code-injection-in-bedrock-agent-import","title":"AWS AgentCore CLI code injection in Bedrock Agent import","severity":"critical","exploited":false,"published_at":"2026-06-08T19:16:41.27+00:00","url":"https://junglewise.ai/threats/cve-2026-11393-aws-agentcore-cli-code-injection-in-bedrock-agent-import"},{"cve":"CVE-2025-4318","cvss":4,"epss":0.0094,"slug":"cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui","title":"AWS Amplify Studio eval injection in amplify-codegen-ui","severity":"critical","exploited":false,"published_at":"2026-07-30T20:57:24+00:00","url":"https://junglewise.ai/threats/cve-2025-4318-aws-amplify-studio-eval-injection-in-amplify-codegen-ui"},{"cve":"CVE-2026-96883","cvss":8.8,"epss":0.0065,"slug":"cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution","title":"pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authen","severity":"high","exploited":false,"published_at":"2026-09-24T20:17:35.24+00:00","url":"https://junglewise.ai/threats/cve-2026-96883-aws-pgcollection-type-confusion-remote-code-execution"},{"cve":"CVE-2026-49473","cvss":8.8,"epss":0.0047,"slug":"cve-2026-49473-aws-cedar-policy-express-js-middleware-authorization-bypass-via","title":"AWS Cedar Policy Express.js middleware authorization bypass via query string manipulation","severity":"high","exploited":false,"published_at":"2026-06-30T18:09:13+00:00","url":"https://junglewise.ai/threats/cve-2026-49473-aws-cedar-policy-express-js-middleware-authorization-bypass-via"},{"cve":"CVE-2026-11401","cvss":8,"epss":0.0031,"slug":"cve-2026-11401-aws-advanced-go-wrapper-privilege-escalation-in","title":"AWS Advanced Go Wrapper privilege escalation in GlobalDatabasePlugin","severity":"high","exploited":false,"published_at":"2026-06-05T20:17:28.883+00:00","url":"https://junglewise.ai/threats/cve-2026-11401-aws-advanced-go-wrapper-privilege-escalation-in"},{"cve":"CVE-2026-18656","cvss":7.8,"epss":0.0022,"slug":"cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory","title":"An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbi","severity":"high","exploited":false,"published_at":"2026-08-04T20:16:50.41+00:00","url":"https://junglewise.ai/threats/cve-2026-18656-kiro-ide-and-cli-executable-resolution-from-untrusted-directory"},{"cve":"CVE-2026-12957","cvss":7.8,"epss":0.0018,"slug":"cve-2026-12957-aws-language-servers-arbitrary-code-execution-in-trusted","title":"AWS Language Servers arbitrary code execution in trusted workspaces","severity":"high","exploited":false,"published_at":"2026-06-23T17:16:40.977+00:00","url":"https://junglewise.ai/threats/cve-2026-12957-aws-language-servers-arbitrary-code-execution-in-trusted"},{"cve":"CVE-2026-5429","cvss":7.8,"epss":0.0016,"slug":"cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview","title":"AWS Kiro IDE arbitrary code execution in Kiro Agent webview","severity":"high","exploited":false,"published_at":"2026-04-02T19:21:37.083+00:00","url":"https://junglewise.ai/threats/cve-2026-5429-aws-kiro-ide-arbitrary-code-execution-in-kiro-agent-webview"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"AWS Cloud Development Kit","slug":"cdk","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/cdk"},{"name":"AWS Kiro IDE","slug":"kiro-ide","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/kiro-ide"},{"name":"AWS-LC","slug":"lc","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/lc"},{"name":"Aws-Lc-Sys","slug":"aws-lc-sys","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/aws-lc-sys"}]}