To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code. | |
| Title | Denial of service in the event stream header decoder in AWS SDK for Go v2 | |
| First Time appeared |
Aws
Aws aws Sdk For Go V2 |
|
| Weaknesses | CWE-248 | |
| CPEs | cpe:2.3:a:aws:aws_sdk_for_go_v2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Sdk For Go V2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-11T19:20:01.797Z
Reserved: 2026-09-10T20:14:45.885Z
Link: CVE-2026-89090
Updated: 2026-09-11T19:19:54.803Z
Status : Awaiting Analysis
Published: 2026-09-11T18:17:00.097
Modified: 2026-09-11T20:19:22.680
Link: CVE-2026-89090
No data.
OpenCVE Enrichment
No data.