CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http
Bulletin ID: 2026-043-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/12/2026 11:45 AM PDT Description: AWS Common Runtime aws-c-http is a HTTP client library used by AWS SDKs for handling http requests to AWS services. We identified CVE-2026-12043, an issue where improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. Impacted versions: aws-c-http >= 0.4.22 AND <= 0.10.15 Exposed in following sdk versions: - aws-sdk-cpp >= 1.11.41, <= 1.11.814 - aws-sdk-java-v2 >= 2.44.27, <= 2.44.14 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Improper handling of HPACK dynamic table size updates may lead to memory corruption and potential arbitrary code execution.
- Who is affected
- Users of aws-c-http within the specified version range.
- Urgency
- Remediation is urgent due to the potential for remote code execution.
- Action
- Update aws-c-http to a version outside the affected range.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch aws-c-http
Get an email when a new aws-c-http advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-043-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-120430.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12043 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - Heap double-free
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2022-50998: Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14…nvd · 2026-08-25
- unknownCVE-2026-72361: In the Linux kernel, the following vulnerability has been resolved: drm/xe/hw_engine: Fix doub…nvd · 2026-08-15
- criticalCVE-2026-72220: In the Linux kernel, the following vulnerability has been resolved: sunrpc: harden rq_procinfo…nvd · 2026-08-15
- unknownCVE-2026-72079: In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix use-a…nvd · 2026-08-15
- highCVE-2026-47895: In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that…msrc · 2026-08-11
- mediumCVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy()msrc · 2026-08-11
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20