bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: aws-c-http

show all
Thursday, August 20, 2026

Critical Heap Double-Free Vulnerability in AWS Common Runtime aws-c-http

AWS Common Runtime aws-c-http has a nasty heap double-free bug (CVE-2026-12043) that lets remote servers trigger memory corruption and potentially execute arbitrary code on your client. If you're using aws-c-http versions 0.4.22 through 0.10.15, or aws-sdk-cpp/aws-sdk-java-v2 within the affected ranges, you need to update immediately. This one's serious—patch ASAP.

source: [aws/security-bulletin]