1sealsemantic last-mile verification

Research / Finding

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

F-AWS-SDK-GO-V2-ES-001

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

5.9medium
CVE-2026-89090CVEaws/aws-sdk-go-v2

Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder

Fixed in: aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory

patched
details
Finding IDs
F-AWS-SDK-GO-V2-ES-001
CVE
CVE-2026-89090
GHSA
GHSA-xmrv-pmrh-hhx2
Status
patched
Fixed in
aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
Recorded credit
reporter: @1seal (accepted); AWS acknowledgement: Oleh Konko (@1seal)
Note
GHSA published on 2026-04-07 for the unknown eventstream header value type panic fixed upstream in #3355. CVE-2026-89090: AMZN CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-11. Score shown is AWS CNA CVSS v3.1; the CNA also publishes a separate CVSS v4.0 assessment.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Upstream CWE
CWE-248
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)

F-AWS-SDK-GO-V2-ES-001: Input / state handling. An unknown eventstream header type triggers an unrecoverable panic. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-AWS-SDK-GO-V2-ES-001

Security area (1seal assessment): Availability. An unknown EventStream header value type causes process termination in the Go decoder. Reviewed 21 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.