Skip to main content

CVE-2026-8178 - Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

Bulletin ID: 2026-028-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 05/08/2026 11:45 AM PDT
 

Description:

Amazon Redshift JDBC Driver is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs). We identified an issue in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context.

Impacted versions: Amazon Redshift JDBC Driver < 2.2.2

Resolution:

This issue has been addressed in Amazon Redshift JDBC Driver version 2.2.2. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

References:

Acknowledgement:

We would like to thank Fushuling for collaborating on this issue through the coordinated issue disclosure process.


Please email aws-security@amazon.com with any security questions or concerns.