Skip to main content

CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

Bulletin ID: 2026-110-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/11/2026 10:00 AM PDT

Description:

An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate.

Impacted versions: < 2026-03-23

Resolution:

This issue has been addressed in versions 2026-03-23 and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Workarounds:

Not applicable.

References:


Please email aws-security@amazon.com with any security questions or concerns.