CVE 8.8 HIGH

Heap double-free in AWS Common Runtime aws-c-http_CVE-2026-12043

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.



To remediate this issue, users should upgrade to aws-c-http version 0.11.0.

AI Analysis

Heap double-free vulnerability in AWS Common Runtime aws-c-http library, potentially allowing arbitrary code execution via crafted HTTP/2 HEADERS frames

Basic Information

ID CVE-2026-12043
Source AMZN
Published Jun 12, 2026 at 18:35
Modified Jun 12, 2026 at 18:49

Affected Product

Vendor AWS
Product aws-c-http
Version 0.4.22
Affected Versions AWS aws-c-http 0.4.22

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Amazon Web Services (AWS)
Product AWS Common Runtime aws-c-http
Version 0.4.22

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.