CVE-2026-35559 Details
Description
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0.
A denial-of-service vulnerability has been identified in the Amazon Athena ODBC driver, specifically in versions prior to 2.1.0.0. The issue arises from an out-of-bounds write in the query processing components, which could allow a threat actor to crash the driver. This vulnerability can be exploited by using specially crafted data that the driver processes during query operations.
Users are advised to upgrade to the Amazon Athena ODBC driver version 2.1.0.0, available through the Amazon Athena ODBC 2.x driver download page. Instructions for downloading the driver on Windows, Linux, and macOS are also available on this page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon athena odbc | < 2.1.0.0 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | AMZN |