Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89090

MEDIUM NVD
CVSS Score 5.9
Severity MEDIUM
Published Sep 11, 2026
Vendor unknown

Description

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.

References