CVE-2026-5190 - AWS C Event Stream Streaming Decoder Stack Buffer Overflow
Bulletin ID: 2026-011-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/31 10:15 AM PDT Description: AWS Common Runtime library is used by several AWS SDKs to communicate with event-stream services (Ex. Kinesis, Transcribe). We identified CVE-2026-5190. AWS Common Runtime event-stream decoder component before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages. Impacted versions: - aws-c-event-stream < 0.6.0and the following higher level libraries that expose event-stream functionality - aws-iot-device-sdk-cpp-v2 < 1.42.1 - aws-iot-device-sdk-java-v2 < 1.30.1 - aws-iot-device-sdk-python-v2 < 1.28.2 - aws-iot-device-sdk-js-v2 < 1.25.1 - aws-sdk-swift < 1.6.70 - aws-sdk-cpp < 1.11.764 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- A stack buffer overflow in the event-stream decoder may allow a third party to cause memory corruption leading to arbitrary code execution.
- Who is affected
- Client applications using AWS Common Runtime versions before 0.6.0.
- Urgency
- Remediation is high priority due to the potential for arbitrary code execution.
- Action
- Upgrade to AWS Common Runtime version 0.6.0 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AWS Common Runtime
Get an email when a new AWS Common Runtime advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-011-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-51900.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-5190 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - AWS C
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-85678: The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against…nvd · 2026-09-11
- mediumCVE-2026-89092: The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a m…nvd · 2026-09-11
- highCVE-2026-82099: IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to exe…nvd · 2026-09-10
- highCVE-2026-82095: IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to exe…nvd · 2026-09-10
- highCVE-2026-81550: IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to exe…nvd · 2026-09-10
- highCVE-2026-88036: Improper neutralization of special elements in data query logic in the GridFS component of the…nvd · 2026-09-10
More from AWS Security Bulletins
- unknownCVE-2026-89049 - Server-side request forgery in the Session Manager port forwarding functionality in AWS Syste…2026-09-10
- unknownCVE-2026-85228 - Integer overflow in tensor buffer validation in Deep Java Library2026-09-10
- unknownCVE-2026-83551 - Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK2026-09-09
- highCVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit2026-09-09
- unknownCVE-2026-18953 - Improper limitation of a pathname in AWS Transform MCP Server2026-09-09