CVE-2019-18960: Amazon Firecracker

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.

Affected products

  • Amazon Firecracker: version 0.18.0 only; version 0.19.0 only

Published 2019-12-11. Last modified 2026-06-17.