mediumCVSS 5.9Vulnerability

GHSA-xmrv-pmrh-hhx2

**CVSSv3.1 Rating**: [Medium] **CVSSv3.1 Score**: [5.9] **CVSSv3.1 Vector String**: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H] ## Summary and Impact An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23). An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) ## Patches This issue has been addressed in versions [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ## Workarounds Not Applicable ## References If you have any questions or comments about this advisory, we ask that you contact [AWS/Amazon] Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Properties

ghsa_id
GHSA-xmrv-pmrh-hhx2
severity
medium
summary
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
cvss_score
5.9
cve_id
GHSA-xmrv-pmrh-hhx2
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-04-08T00:18:56Z
source_url
https://github.com/advisories/GHSA-xmrv-pmrh-hhx2
ghsa_updated
2026-04-08T00:18:59Z

Related Entities (26)

VULNERABLE_TO (12)

←[Software]go/github.com/aws/aws-sdk-go-v2/service/sagemakerruntime
←[Software]go/github.com/aws/aws-sdk-go-v2/service/transcribestreaming
←[Software]go/github.com/aws/aws-sdk-go-v2/service/s3
←[Software]go/github.com/aws/aws-sdk-go-v2/service/lexruntimev2
←[Software]go/github.com/aws/aws-sdk-go-v2/service/iotsitewise
←[Software]go/github.com/aws/aws-sdk-go-v2/service/kinesis
←[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockruntime
←[Software]go/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
←[Software]go/github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs
←[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime
←[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentcore
←[Software]go/github.com/aws/aws-sdk-go-v2/service/lambda

AFFECTS (12)

→[Software]go/github.com/aws/aws-sdk-go-v2/service/lambda
→[Software]go/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
→[Software]go/github.com/aws/aws-sdk-go-v2/service/sagemakerruntime
→[Software]go/github.com/aws/aws-sdk-go-v2/service/kinesis
→[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentcore
→[Software]go/github.com/aws/aws-sdk-go-v2/service/transcribestreaming
→[Software]go/github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs
→[Software]go/github.com/aws/aws-sdk-go-v2/service/s3
→[Software]go/github.com/aws/aws-sdk-go-v2/service/iotsitewise
→[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockruntime
→[Software]go/github.com/aws/aws-sdk-go-v2/service/lexruntimev2
→[Software]go/github.com/aws/aws-sdk-go-v2/service/bedrockagentruntime

HAS_WEAKNESS (1)

→[Weakness]Improper Input Validation

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph