Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-89090

Опубликовано: 11 сент. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.

A flaw was found in the event stream header decoder of the Amazon AWS SDK for Go v2. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted event stream response frame. This frame, containing a header value type outside the valid range, would cause an unrecovered panic, leading to the termination of the consuming application process and resulting in a Denial of Service (DoS).

Отчет

A flaw in AWS SDK for Go v2 can cause an application to terminate when it processes an attacker-controlled EventStream response with a crafted header.

Меры по смягчению последствий

Upgrade affected AWS SDK for Go v2 modules to the fixed releases published after 2026-03-23. There is no documented workaround.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
AWS Load Balancer Operatoralbo/aws-load-balancer-rhel8-operatorOut of support scope
AWS Load Balancer Operatoralbo/aws-load-balancer-rhel9-operatorFix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-acmesolver-rhel9Fix deferred
cert-manager Operator for Red Hat OpenShiftcert-manager/jetstack-cert-manager-rhel9Fix deferred
Compliance Operatorcompliance/openshift-compliance-operator-bundleFix deferred
Compliance Operatorcompliance/openshift-compliance-rhel8-operatorFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2531982github.com/aws/aws-sdk-go-v2: Amazon AWS SDK for Go v2: Denial of Service via crafted event stream header

EPSS

Процентиль: 24%
0.00309
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
12 дней назад

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.

EPSS

Процентиль: 24%
0.00309
Низкий

5.9 Medium

CVSS3