CVE-2026-5190: CWE-787: Out-of-bounds Write in AWS aws-c-event-stream
CVE-2026-5190 is a high-severity out-of-bounds write vulnerability in the aws-c-event-stream library before version 0.6.0. It affects the streaming decoder component and can be triggered by a malicious server sending crafted event-stream messages. This flaw may cause memory corruption in client applications, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 7.5, indicating a significant risk. A patch is available by upgrading to version 0.6.0 or later.
AI Analysis
Technical Summary
CVE-2026-5190 is an out-of-bounds write vulnerability classified under CWE-787 in the aws-c-event-stream library versions prior to 0.6.0. The issue resides in the streaming decoder component where processing specially crafted event-stream messages from a malicious server can cause memory corruption on the client side. This memory corruption could enable an attacker to execute arbitrary code within the context of the affected client application. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting network attack vector with high impact on confidentiality, integrity, and availability, but requiring user interaction and high attack complexity. Remediation involves upgrading the library to version 0.6.0 or later.
Potential Impact
Successful exploitation of this vulnerability can lead to arbitrary code execution on client systems using vulnerable versions of aws-c-event-stream. This compromises confidentiality, integrity, and availability of the affected client application. No known exploits are currently reported in the wild.
Mitigation Recommendations
A fix is available by upgrading aws-c-event-stream to version 0.6.0 or later. Users should apply this update promptly to mitigate the vulnerability. Since this is a client-side library, upgrading the dependency in client applications is required. No additional vendor advisories indicate alternative mitigations or that no action is required.
CVE-2026-5190: CWE-787: Out-of-bounds Write in AWS aws-c-event-stream
Description
CVE-2026-5190 is a high-severity out-of-bounds write vulnerability in the aws-c-event-stream library before version 0.6.0. It affects the streaming decoder component and can be triggered by a malicious server sending crafted event-stream messages. This flaw may cause memory corruption in client applications, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 7.5, indicating a significant risk. A patch is available by upgrading to version 0.6.0 or later.
CVSS v3.1
Score 7.5high
Affected software
pkg:github/awslabs/aws-c-event-streamRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5190 is an out-of-bounds write vulnerability classified under CWE-787 in the aws-c-event-stream library versions prior to 0.6.0. The issue resides in the streaming decoder component where processing specially crafted event-stream messages from a malicious server can cause memory corruption on the client side. This memory corruption could enable an attacker to execute arbitrary code within the context of the affected client application. The vulnerability has a CVSS 3.1 base score of 7.5, reflecting network attack vector with high impact on confidentiality, integrity, and availability, but requiring user interaction and high attack complexity. Remediation involves upgrading the library to version 0.6.0 or later.
Potential Impact
Successful exploitation of this vulnerability can lead to arbitrary code execution on client systems using vulnerable versions of aws-c-event-stream. This compromises confidentiality, integrity, and availability of the affected client application. No known exploits are currently reported in the wild.
Mitigation Recommendations
A fix is available by upgrading aws-c-event-stream to version 0.6.0 or later. Users should apply this update promptly to mitigate the vulnerability. Since this is a client-side library, upgrading the dependency in client applications is required. No additional vendor advisories indicate alternative mitigations or that no action is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- AMZN
- Date Reserved
- 2026-03-30T20:05:41.435Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69cc068ae6bfc5ba1d2beeed
Added to database: 03/31/2026, 17:38:18 UTC
Last enriched: 06/05/2026, 19:30:52 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 149
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.