CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
Sdk For ยท 2026-09-11
Actions
Technical Details
| Affected Versions | < 2026-03-23 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-89090 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the AWS SDK for Go v2 to version 2026-03-23 or above to address the security vulnerability CVE-2026-89090 and prevent potential denial of service attacks.
For Platform Teams
Deploy the patched version of the AWS SDK for Go v2 to enhance security and prevent denial of service attacks.
For Executives
Implement the latest AWS SDK for Go v2 to mitigate the risk of denial of service attacks and ensure system stability.
Source
Related Sdk For Updates
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ (2026-09-09)
- Introducing a standalone SigV4 signer for the AWS SDK for .NET (2026-08-31)
- CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python (2026-08-20)
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ (2026-08-20)
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ (2026-08-12)