Vulnerabilities in AWS

140 results
Vexday analysis

Com 69 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil do AWS situa-se abaixo da média geral do catálogo nesse indicador, o que representa um panorama relativamente controlado em termos de ameaças imediatas. No entanto, 33 vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo elevado de descobertas recentes que exige acompanhamento contínuo. O tipo de falha mais recorrente é CWE-327 (uso de algoritmo criptográfico quebrado ou arriscado), padrão que tende a impactar a confidencialidade e integridade de dados em escala. A CVE mais relevante no momento, CVE-2025-0851, apresenta score EPSS de 0,23, e embora existam 3 CVEs com prova de conceito pública e 5 de severidade crítica, nenhuma delas atingiu exploração confirmada até o momento — condição que pode mudar rapidamente diante da disponibilidade de PoCs.

CVE-2026-16756HIGHAllocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of serviceEPSS 0.8%CVE-2026-15957HIGHUncontrolled recursion in smithy-rs generated JSON, CBOR, and XML deserializers allows unauthenticated remote denial of service via recursive shapesEPSS 0.8%CVE-2026-14265HIGHRCE via Deserialization in AWS Advanced JDBC WrapperEPSS 0.7%CVE-2026-16796HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.7%CVE-2022-24709HIGHCross site scripting in @awsui/components-reactEPSS 0.7%CVE-2026-18428HIGHSQL Query Validation Bypass in OpenSearch Direct QueryEPSS 0.7%CVE-2026-13763HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAFEPSS 0.7%CVE-2026-18245MEDIUMIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-reactEPSS 0.7%CVE-2026-18420HIGHRCE via Prototype Pollution in OpenSearch DashboardsEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%CVE-2025-3048MEDIUMPath Traversal in AWS SAM CLI allows file copy to local cacheEPSS 0.6%CVE-2026-13762HIGHHTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAFEPSS 0.6%CVE-2022-46174MEDIUMRace condition during concurrent TLS mounts in efs-utilsEPSS 0.6%CVE-2026-12283MEDIUMSQL injection in Amazon Athena Synapse connectorEPSS 0.6%CVE-2026-14471HIGHAuthenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registryEPSS 0.6%CVE-2026-14904HIGHRES Auth.GetUserPrivateKey Arbitrary File ReadEPSS 0.6%CVE-2026-6912HIGHPrivilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops WheelEPSS 0.6%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.5%CVE-2026-18830HIGHInsufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness APIEPSS 0.5%CVE-2026-6968HIGHMultiple Path Traversal Variants in awslabs/toughEPSS 0.5%