CVE-2026-89090: Aws SDK For Go v2
Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.
Affected products
- Aws Aws SDK For Go v2: before 2026-03-23 (fixed in 2026-03-23)
Published 2026-09-11. Last modified 2026-09-11.