CVE-2026-35562 Details
Description
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should upgrade to version 2.1.0.0.
A denial-of-service vulnerability has been identified in the Amazon Athena ODBC driver, prior to version 2.1.0.0. The issue arises from the parsing components of the driver, which allocate resources without limits. This flaw could be exploited by a threat actor who delivers crafted input that triggers excessive resource consumption during the driver's parsing operations.
Users are advised to upgrade to the Amazon Athena ODBC driver version 2.1.0.0 or later. The updated driver is available for Windows, Linux, and macOS. For detailed download instructions, refer to the Amazon Athena ODBC 2.x release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon athena odbc | < 2.1.0.0 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Apr 3, 2026 | New CVE Received | AMZN |