CVE-2026-22611 Details
Description
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. This issue has been patched in version 4.0.3.3.
A vulnerability exists in the AWS SDK for .NET, specifically in version 4.0.0 prior to 4.0.3.3. This issue allows customer applications to improperly route AWS API calls to non-existent or non-AWS hosts by exploiting invalid region values. An actor with access to the SDK environment could manipulate the region input to an incorrect value, leading to misrouted API calls. Although the SDK operated within the shared responsibility model's safety requirements, this vulnerability highlighted the need for additional safeguards in customer implementations.
Users are advised to update to version 4.0.3.3 or later, and to follow AWS security best practices for SDK configuration. Regularly updating the AWS SDK for .NET to the latest release is also recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 10, 2026CISA-ADP
Assessed Jan 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/aws/aws-sdk-net/security/advisories/GHSA-9cvc-h2w8-phrp | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AWS SDK for .NET | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 10, 2026 | New CVE Received | [email protected] |
Volerion