CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
Bulletin ID: 2026-110-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate.
Impacted versions: < 2026-03-23
Resolution:
This issue has been addressed in versions 2026-03-23 and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
Not applicable.
References:
Please email aws-security@amazon.com with any security questions or concerns.