CVE-2026-5190 Details
Description
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. To remediate this issue, users should upgrade to version 0.6.0 or later.
A stack buffer overflow vulnerability has been identified in the streaming decoder component of the AWS C Event Stream library, prior to version 0.6.0. This vulnerability could allow a third party operating a server to cause memory corruption, leading to arbitrary code execution on a client application that processes crafted event-stream messages. The issue arises when the client communicates with an untrusted server using the event-stream protocol, a scenario that can occur with certain AWS SDKs.
Users should upgrade to AWS C Event Stream version 0.6.0 or later. This vulnerability has also been addressed in the following AWS SDK libraries: AWS IoT Device SDK C++ V2 version 1.42.1, AWS IoT Device SDK Java V2 version 1.30.1, AWS IoT Device SDK Python V2 version 1.28.2, AWS IoT Device SDK JavaScript V2 version 1.25.1, AWS SDK for Swift version 1.6.70, and AWS SDK for C++ version 1.11.764.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | AMZN |