PT-2026-29320 · Amazon · Aws-C-Event-Stream

·

CVE-2026-5190

·

Published

2026-03-31

·

Updated

2026-07-24

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions aws-c-event-stream versions prior to 0.6.0
Description A flaw exists in the streaming decoder component of aws-c-event-stream that could allow a third party operating a server to cause memory corruption, potentially leading to arbitrary code execution on a client application that processes specially crafted event-stream messages.
Recommendations Upgrade to version 0.6.0 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5190
GHSA-XVJW-FJQ5-68HF
OPENSUSE-SU-2026:10512-1
OPENSUSE-SU-2026:20477-1

Affected Products

Aws-C-Event-Stream