CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http
Bulletin ID: 2026-043-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/12/2026 11:45 AM PDT Description: AWS Common Runtime aws-c-http is a HTTP client library used by AWS SDKs for handling http requests to AWS services. We identified CVE-2026-12043, an issue where improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. Impacted versions: aws-c-http >= 0.4.22 AND <= 0.10.15 Exposed in following sdk versions: - aws-sdk-cpp >= 1.11.41, <= 1.11.814 - aws-sdk-java-v2 >= 2.44.27, <= 2.44.14 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Improper handling of HPACK dynamic table size updates may lead to memory corruption and potential arbitrary code execution.
- Who is affected
- Users of aws-c-http within the specified version range.
- Urgency
- Remediation is urgent due to the potential for remote code execution.
- Action
- Update aws-c-http to a version outside the affected range.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch aws-c-http
Get an email when a new aws-c-http advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-043-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-120430.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12043 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - Heap double-free
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-61915: An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An…nvd · 2026-09-09
- highCVE-2026-33630: c-ares : Use-after-free / double-free in c-ares query-completion handling, remotely triggerabl…msrc · 2026-09-08
- highCVE-2026-33630: c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / d…nvd · 2026-09-03
- unknownCVE-2026-19316: A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthe…nvd · 2026-08-28
- highCVE-2022-50998: Nokogiri before 1.13.9 (CRuby implementation using packaged libraries) bundles libxml2 v2.9.14…nvd · 2026-08-25
- unknownCVE-2026-72361: In the Linux kernel, the following vulnerability has been resolved: drm/xe/hw_engine: Fix doub…nvd · 2026-08-15
More from AWS Security Bulletins
- unknownCVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Syste…2026-09-10
- unknownCVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library2026-09-10
- unknownCVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK2026-09-09
- highCVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit2026-09-09
- unknownCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server2026-09-09