mediumCVSS 5.9Vulnerability

GHSA-xmrv-pmrh-hhx2

**CVSSv3.1 Rating**: [Medium] **CVSSv3.1 Score**: [5.9] **CVSSv3.1 Vector String**: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H] ## Summary and Impact An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23). An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) ## Patches This issue has been addressed in versions [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ## Workarounds Not Applicable ## References If you have any questions or comments about this advisory, we ask that you contact [AWS/Amazon] Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Properties

ghsa_id
GHSA-xmrv-pmrh-hhx2
severity
medium
summary
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
cvss_score
5.9
cve_id
GHSA-xmrv-pmrh-hhx2
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-04-08T00:18:56Z
source_url
https://github.com/advisories/GHSA-xmrv-pmrh-hhx2
ghsa_updated
2026-04-08T00:18:59Z

Related Entities (26)

VULNERABLE_TO (12)

[Software]go/github.com/aws/aws-sdk-go-v2/service/sagemakerruntime
[Software]go/github.com/aws/aws-sdk-go-v2/service/transcribestreaming
[Software]go/github.com/aws/aws-sdk-go-v2/service/s3
[Software]go/github.com/aws/aws-sdk-go-v2/service/lexruntimev2
[Software]go/github.com/aws/aws-sdk-go-v2/service/iotsitewise
[Software]go/github.com/aws/aws-sdk-go-v2/service/kinesis
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockruntime
[Software]go/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
[Software]go/github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentcore
[Software]go/github.com/aws/aws-sdk-go-v2/service/lambda

AFFECTS (12)

[Software]go/github.com/aws/aws-sdk-go-v2/service/lambda
[Software]go/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
[Software]go/github.com/aws/aws-sdk-go-v2/service/sagemakerruntime
[Software]go/github.com/aws/aws-sdk-go-v2/service/kinesis
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentcore
[Software]go/github.com/aws/aws-sdk-go-v2/service/transcribestreaming
[Software]go/github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs
[Software]go/github.com/aws/aws-sdk-go-v2/service/s3
[Software]go/github.com/aws/aws-sdk-go-v2/service/iotsitewise
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockruntime
[Software]go/github.com/aws/aws-sdk-go-v2/service/lexruntimev2
[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph