CVE-2026-12043: Aws Aws-C-HTTP

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.

Affected products

  • Aws Aws-C-HTTP: from 0.4.22, up to and including 0.10.15

Published 2026-06-12. Last modified 2026-06-17.