8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
AI Analysis
Heap double-free vulnerability in AWS Common Runtime aws-c-http library, potentially allowing arbitrary code execution via crafted HTTP/2 HEADERS frames
Basic Information
ID
CVE-2026-12043
Source
AMZN
Published
Jun 12, 2026 at 18:35
Modified
Jun 12, 2026 at 18:49
Affected Product
Vendor
AWS
Product
aws-c-http
Version
0.4.22
Affected Versions
AWS aws-c-http 0.4.22
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Amazon Web Services (AWS)
Product
AWS Common Runtime aws-c-http
Version
0.4.22