Impact
The vulnerability is an unrecovered panic triggered by the event stream header decoder when it encounters a header value type outside the expected range. The panic crashes the consuming application, effectively denying service to legitimate users. This weakness is an uncaught exception, classified as CWE‑248. The problem exists in all builds of AWS SDK for Go v2 prior to release‑2026‑03‑23 and can be exploited by sending a crafted event stream response frame.
Affected Systems
AWS SDK for Go v2 is impacted. Any project or derivative fork that incorporates the SDK before release‑2026‑03‑23 is vulnerable. The affected code base includes the event stream header decoding logic for all releases before the mentioned version.
Risk and Exploitability
The CVSS score of 8.2 denotes high severity. EPSS indicates a very low probability of exploitation, though not zero. The attack is remote, unauthenticated, and requires that an attacker can inject a malicious event stream response frame with an invalid header type. No additional prerequisites are necessary beyond the ability to deliver such a frame, and the vulnerability is not present in the CISA KEV catalog.
OpenCVE Enrichment