Critical Heap Double-Free Vulnerability in AWS Common Runtime aws-c-http
AWS Common Runtime aws-c-http has a nasty heap double-free bug (CVE-2026-12043) that lets remote servers trigger memory corruption and potentially execute arbitrary code on your client. If you're using aws-c-http versions 0.4.22 through 0.10.15, or aws-sdk-cpp/aws-sdk-java-v2 within the affected ranges, you need to update immediately. This one's serious—patch ASAP.
source: [aws/security-bulletin]