Description
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range.



To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Published: 2026-09-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an unrecovered panic triggered by the event stream header decoder when it encounters a header value type outside the expected range. The panic crashes the consuming application, effectively denying service to legitimate users. This weakness is an uncaught exception, classified as CWE‑248. The problem exists in all builds of AWS SDK for Go v2 prior to release‑2026‑03‑23 and can be exploited by sending a crafted event stream response frame.

Affected Systems

AWS SDK for Go v2 is impacted. Any project or derivative fork that incorporates the SDK before release‑2026‑03‑23 is vulnerable. The affected code base includes the event stream header decoding logic for all releases before the mentioned version.

Risk and Exploitability

The CVSS score of 8.2 denotes high severity. EPSS indicates a very low probability of exploitation, though not zero. The attack is remote, unauthenticated, and requires that an attacker can inject a malicious event stream response frame with an invalid header type. No additional prerequisites are necessary beyond the ability to deliver such a frame, and the vulnerability is not present in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 04:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade AWS SDK for Go v2 to release‑2026‑03‑23 or later.
  • Apply the same patch to any forked or derivative SDK code supervision or health checks to automatically restart services that crash from SDK panics, minimizing downtime until a formal update is applied.
  • Lock the dependency to the patched SDK version in your Go module file (go.mod) and enforce it in CI/CD to prevent accidental use of vulnerable releases.

Generated by OpenCVE AI on September 21, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Title Denial of service in the event stream header decoder in AWS SDK for Go v2
First Time appeared Aws
Aws aws Sdk For Go V2
Weaknesses CWE-248
CPEs cpe:2.3:a:aws:aws_sdk_for_go_v2:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws aws Sdk For Go V2
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Aws Aws Sdk For Go V2
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-24T19:29:25.970Z

Reserved: 2026-09-10T20:14:45.885Z

Link: CVE-2026-89090

cve-icon Vulnrichment

Updated: 2026-09-11T19:19:54.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-11T18:17:00.097

Modified: 2026-09-11T20:19:22.680

Link: CVE-2026-89090

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T17:03:33Z

Links: CVE-2026-89090 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:30:08Z

Weaknesses