Description
An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input.



To remediate this issue, users should upgrade to version 1.11.862.
Published: 2026-08-12
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Base64 decoder of Amazon aws‑sdk‑cpp allows an out‑of‑bounds write which can overwrite adjacent heap memory. The defect can trigger a crash or result in heap memory corruption. The vulnerability is classified as CWE‑787 and permits a remote authenticated user to supply crafted Base64 data that will be processed by any application linked to the affected SDK.

Affected Systems

AWS aws‑sdk‑cpp before version 1.11.862 is affected. Updating to 1.11.862 or newer removes the vulnerability.

Risk and Exploitability

The CVSS score of 6 indicates a medium severity risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to an application that uses the vulnerable SDK and to supply malicious Base64 input, so the attack vector is remote authenticated. The lack of public exploits suggests it is not yet widely abused, but the risk of heap corruption remains significant.

Generated by OpenCVE AI on August 12, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to aws‑sdk‑cpp version 1.11.862 or later
  • Implement strict validation on all Base64 input, rejecting inputs that exceed expected size or contain non‑standard characters
  • For critical deployments, consider isolating services that use the SDK in hardened runtimes or containers to limit the impact of a potential heap corruption

Generated by OpenCVE AI on August 12, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 20:15:00 +0000


Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Title Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp
First Time appeared Aws
Aws aws-sdk-cpp
Weaknesses CWE-787
CPEs cpe:2.3:a:aws:aws-sdk-cpp:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws-sdk-cpp
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-08-12T19:44:01.502Z

Reserved: 2026-08-12T16:49:37.222Z

Link: CVE-2026-19642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-12T20:17:42.653

Modified: 2026-08-12T20:50:27.407

Link: CVE-2026-19642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T23:15:03Z

Weaknesses