PT-2026-29320 · Aws · Aws-C-Event-Stream

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-5190

CVSS v3.1

7.5

High

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.
To remediate this issue, users should upgrade to version 0.6.0 or later.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2026-5190

Affected Products

Aws-C-Event-Stream