Описание
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.
To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
A flaw was found in the event stream header decoder of the Amazon AWS SDK for Go v2. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted event stream response frame. This frame, containing a header value type outside the valid range, would cause an unrecovered panic, leading to the termination of the consuming application process and resulting in a Denial of Service (DoS).
Отчет
A flaw in AWS SDK for Go v2 can cause an application to terminate when it processes an attacker-controlled EventStream response with a crafted header.
Меры по смягчению последствий
Upgrade affected AWS SDK for Go v2 modules to the fixed releases published after 2026-03-23. There is no documented workaround.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| AWS Load Balancer Operator | albo/aws-load-balancer-rhel8-operator | Out of support scope | ||
| AWS Load Balancer Operator | albo/aws-load-balancer-rhel9-operator | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-acmesolver-rhel9 | Fix deferred | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Fix deferred | ||
| Compliance Operator | compliance/openshift-compliance-operator-bundle | Fix deferred | ||
| Compliance Operator | compliance/openshift-compliance-rhel8-operator | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-must-gather-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-builder-rhel9 | Fix deferred | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
EPSS
5.9 Medium
CVSS3