highVulnerability

GHSA-443w-3rq3-5m5h

### Summary This notification is related to the [CloudFront signing utilities](https://github.com/aws/aws-sdk-java-v2/blob/master/services/cloudfront/src/main/java/software/amazon/awssdk/services/cloudfront/CloudFrontUtilities.java) in the AWS SDK for Java v2, which are used to generate Amazon CloudFront signed URLs and signed cookies. A defense-in-depth enhancement has been implemented to improve handling of special characters, such as double quotes and backslashes, in input values. ### Impact The CloudFront signing utilities build policy documents that define access restrictions for signed URLs and cookies. If an application passes unsanitized input containing special characters to these utilities, the resulting policy document may not reflect the application's intended access restrictions. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Applications that already follow AWS security best practices for input validation are not impacted. ### Impacted versions: 2.18.33 - 2.41.29 ### Patches On 2026.02.16, an enhancement was made to AWS SDK for Java v2 version 2.41.30. The enhancement ensures that special characters in input values are correctly handled. We recommend upgrading to the latest version. ### Workarounds No workarounds are needed, but customers should ensure that your application is following security best practices: * Implement proper input validation in your application code before passing values to CloudFront signing utilities * Update to the latest AWS SDK release on a regular basis * Follow [AWS security best practices for SDK configuration](https://docs.aws.amazon.com/sdk-for-java/latest/developer-guide/security.html) ### Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via our vulnerability reporting page or directly via email to [[email protected]](mailto:aws-se

Properties

ghsa_id
GHSA-443w-3rq3-5m5h
severity
high
summary
AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities
cve_id
GHSA-443w-3rq3-5m5h
is_ghsa_only
true
ghsa_published
2026-03-27T20:43:16Z
source_url
https://github.com/advisories/GHSA-443w-3rq3-5m5h
ghsa_updated
2026-03-27T20:43:17Z

Related Entities (4)

AFFECTS (1)

[Software]maven/software.amazon.awssdk:cloudfront

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Improper Encoding or Escaping of Output

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph