CVE-2026-12043 Details
Description
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
A heap double-free vulnerability has been identified in the AWS Common Runtime aws-c-http library, which is used by AWS SDKs to manage HTTP requests to AWS services. This vulnerability arises from improper handling of HPACK dynamic table size updates, which could enable a remote server operator to craft a sequence of HTTP/2 HEADERS frames that causes memory corruption in a connected client application. Such corruption could potentially lead to arbitrary code execution.
Users should upgrade to aws-c-http version 0.11.0. This vulnerability also affects aws-sdk-cpp versions 1.11.41 through 1.11.814 and aws-sdk-java-v2 versions 2.44.27 through 2.44.14. For these SDKs, upgrading to a version that includes the patched aws-c-http library is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-415 | Double Free | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | CVE Modified | AMZN |
| Jun 12, 2026 | New CVE Received | AMZN |