1sealsemantic last-mile verification

Research / Finding

AWS event-stream: decoder buffer write

F-AWS-EVENT-STREAM-001

Read the full technical write-up →

Root cause, affected code and disclosure timeline.

At a glance

Conditions
A client processing attacker-controlled event-stream headers can reach an out-of-bounds write in the streaming decoder.
What to do
Upgrade aws-c-event-stream to v0.6.0 or later and affected AWS SDK for C++ builds to the vendor's fixed version below. Check lock files as well: the AWS Common Runtime can pin an older version as a transitive dependency.

1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.

Fix and severity by source

Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

7.7high
CVE-2026-5190CVEaws/aws-sdk-cpp

Memory Corruption in event-stream parsing of headers

Fixed in: aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764

patched
details
Finding IDs
F-AWS-EVENT-STREAM-001
CVE
CVE-2026-5190
GHSA
GHSA-xvjw-fjq5-68hf
Status
patched
Fixed in
aws-c-event-stream 0.6.0; aws-sdk-cpp 1.11.764
Recorded credit
acknowledgement: Oleh Konko from 1seal / 1seal.org
Note
GHSA-xvjw-fjq5-68hf / AWS-2026-011; AWS Common Runtime event-stream decoder memory corruption affecting aws-sdk-cpp <1.11.764 and other SDKs that expose event-stream functionality.
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Memory Corruption in event-stream parsing of headers
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
No structured @1seal credit in this snapshot; textual acknowledgements may exist.

F-AWS-EVENT-STREAM-001: Memory safety. An unbounded header-name length leads to an out-of-bounds write. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-EVENT-STREAM-001

Security area (1seal assessment): Memory safety. Crafted event-stream messages can corrupt decoder memory in a client application. Reviewed 21 Sep 2026.

8.1high
1SEAL-2026-0011SEAL advisoryawslabs/aws-c-event-stream

remote out-of-bounds write in streaming decoder

Fixed in: v0.6.0

Fix recordednot counted
details
Finding IDs
F-AWS-EVENT-STREAM-001
CVE
CVE-2026-5190
Status
patched
CWE
CWE-787
Fixed in
v0.6.0
Disclosure date
Recorded severity
high
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

F-AWS-EVENT-STREAM-001: Memory safety. An unbounded header-name length leads to an out-of-bounds write. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-EVENT-STREAM-001

Security area (1seal assessment): Memory safety. The streaming decoder writes beyond its header-name buffer; this is another record of the same AWS event-stream finding. Reviewed 21 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.