Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Fixed in: aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
details
- Finding IDs
- F-AWS-SDK-GO-V2-ES-001
- CVE
- CVE-2026-89090
- GHSA
- GHSA-xmrv-pmrh-hhx2
- Status
- patched
- Fixed in
- aws/protocol/eventstream v1.7.8; service-specific versions listed in the advisory
- Recorded credit
- reporter: @1seal (accepted); AWS acknowledgement: Oleh Konko (@1seal)
- Note
- GHSA published on 2026-04-07 for the unknown eventstream header value type panic fixed upstream in #3355. CVE-2026-89090: AMZN CNA record verified PUBLISHED on 2026-09-23; CVE publication 2026-09-11. Score shown is AWS CNA CVSS v3.1; the CNA also publishes a separate CVSS v4.0 assessment.
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
- Upstream CWE
- CWE-248
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-AWS-SDK-GO-V2-ES-001: Input / state handling. An unknown eventstream header type triggers an unrecoverable panic. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-SDK-GO-V2-ES-001
Security area (1seal assessment): Availability. An unknown EventStream header value type causes process termination in the Go decoder. Reviewed 21 Sep 2026.