CVE-2026-19643
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input.
To remediate this issue, users should upgrade to version 1.11.862.
CSIRTS triage
- What
- Out-of-bounds write and read vulnerabilities in the Base64 decoder component of the AWS SDK for C++.
- Who is affected
- Applications using AWS SDK for C++ that process untrusted Base64-encoded input via the SDK.
- Urgency
- Moderate; out-of-bounds memory access can cause crashes or memory corruption but RCE has not been demonstrated.
- Action
- Update AWS SDK for C++ to a patched version and review code paths that decode untrusted Base64 data.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-19643
Get an email if CVE-2026-19643 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-19643)