Vulnerabilidades em aws
110 resultadosAnálise Vexday
A AWS apresenta 13 vulnerabilidades cadastradas na base, com apenas 1 classificada como crítica; nenhuma está sob ataque ativo (KEV) e nenhuma foi divulgada nos últimos 90 dias, indicando risco contido e sem pressão imediata. A fraqueza dominante é a traversal de diretórios (CWE-22), sugerindo exposição a acesso não autorizado de arquivos em condições específicas, embora a ausência de exploração ativa mitigue a urgência.
CVE-2026-12530HIGHImproper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()EPSS 0.3%CVE-2026-18394MEDIUMIncorrect authorization in Strands Agents Tools http_request proxy credential exfiltrationEPSS 0.3%CVE-2025-12815MEDIUMAn ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.EPSS 0.3%CVE-2026-18830HIGHInsufficient input validation in Amazon Bedrock AgentCore harness InvokeHarness APIEPSS 0.3%CVE-2026-10740MEDIUMExcessive memory allocation in s2n-quicEPSS 0.3%CVE-2026-18654MEDIUMDisabled SSH host key verification in Amazon AWS CLI EMR helper commandsEPSS 0.3%CVE-2025-11617MEDIUMBuffer Over-read when receiving IPv6 packets with incorrect payload length in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2025-11616MEDIUMBuffer Over-read when receiving improperly sized ICMPv6 packets in FreeRTOS-Plus-TCPEPSS 0.3%CVE-2026-18481MEDIUMStored XSS in Participant URL Field leads to Account Takeover via Session Token TheftEPSS 0.3%CVE-2026-6966HIGHSignature Threshold Bypass in awslabs/tough Delegated RolesEPSS 0.3%CVE-2025-2598MEDIUMAWS CDK CLI prints AWS credentials retrieved by custom credential pluginsEPSS 0.3%CVE-2026-6911CRITICALAuthentication Bypass via Missing JWT Signature Verification in AWS Ops WheelEPSS 0.3%CVE-2026-18655HIGHBroker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt InjectionEPSS 0.3%CVE-2026-4428CRITICALCRL Distribution Point Scope Check Logic Error in AWS-LCEPSS 0.3%CVE-2026-15415MEDIUMPath traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-serverEPSS 0.2%CVE-2026-7426MEDIUMOut-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plus-TCPEPSS 0.2%CVE-2026-6967HIGHMissing Delegated Metadata Validation in awslabs/toughEPSS 0.2%CVE-2025-0508MEDIUMMD5 Hash Collision in SageMaker Workflow in aws/sagemaker-python-sdkEPSS 0.2%CVE-2026-1778HIGHTLS disabled by default in select aws/sagemaker-python-sdk configurationsEPSS 0.2%CVE-2026-4269MEDIUMImproper S3 ownership verification in Bedrock AgentCore Starter ToolkitEPSS 0.2%