
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5190 is a stack buffer overflow (out-of-bounds write) vulnerability in the streaming decoder component of aws-c-event-stream, an AWS Common Runtime library used by multiple AWS SDKs for event-stream protocol communication. A third party operating a server can send specially crafted event-stream messages to cause memory corruption, potentially leading to arbitrary code execution on the client application. The vulnerability affects aws-c-event-stream versions before 0.6.0, as well as several higher-level SDK libraries that expose event-stream functionality. It was published on March 31, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 7.7 (High) (AWS Security Bulletin, GitHub Advisory).
The root cause is an out-of-bounds write (CWE-787) in the event-stream header parsing logic of the streaming decoder component. When a client application processes event-stream messages from a server, insufficient bounds checking allows a malicious server to supply crafted header data that overflows a stack buffer, corrupting adjacent memory. Exploitation requires high attack complexity (the attacker must control the server the client connects to) and passive user interaction (the client must initiate a connection and process messages). The fix, released as v0.6.0, addresses a possible overflow in the decode buffer, as noted in the GitHub release (GitHub Release, GitHub Advisory).
Successful exploitation allows a threat actor controlling a server to cause memory corruption on a connecting client application, potentially achieving arbitrary code execution with the privileges of the client process. This could result in full compromise of confidentiality, integrity, and availability of the affected client system. Notably, AWS-operated services such as AWS Transcribe and AWS Kinesis are not impacted — the risk is limited to scenarios where a client communicates with a third-party or attacker-controlled server using the event-stream protocol (AWS Security Bulletin, GitHub Advisory).
aws-c-event-stream < 0.6.0 or affected SDK versions (e.g., aws-iot-device-sdk-cpp-v2 < 1.42.1, aws-sdk-cpp < 1.11.764) and communicate with non-AWS event-stream servers.aws-c-event-stream.AWS has released patched versions addressing this vulnerability. Users should upgrade to the following minimum versions: aws-c-event-stream ≥ 0.6.0, aws-iot-device-sdk-cpp-v2 ≥ 1.42.1, aws-iot-device-sdk-java-v2 ≥ 1.30.1, aws-iot-device-sdk-python-v2 ≥ 1.28.2, aws-iot-device-sdk-js-v2 ≥ 1.25.1, aws-sdk-swift ≥ 1.6.70, and aws-sdk-cpp ≥ 1.11.764. As a workaround for those unable to upgrade immediately, ensure that client applications only communicate with trusted servers using the event-stream protocol, as AWS-operated servers will not trigger this issue. Any forked or derivative code incorporating aws-c-event-stream should also be patched (AWS Security Bulletin, GitHub Advisory).
The vulnerability was discovered and responsibly disclosed by Oleh Konko from 1seal.org through coordinated vulnerability disclosure with AWS Security. AWS published a security bulletin (2026-011-AWS) and a GitHub Security Advisory (GHSA-xvjw-fjq5-68hf) on March 31, 2026. OpenSUSE issued a security announcement for its packaged version of aws-c-event-stream, and Tenable added a Nessus detection plugin (ID 305836). Community discussion was limited, with brief mentions on Mastodon and security feed aggregators (AWS Security Bulletin, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."