Amazon Web Services

aws.amazon.com

Imported from official source

Cloud provider; publisher of security bulletins.

Type
Company
Scope
US · global
Website
aws.amazon.com
Feed
Atom

Publications 65

  1. CVE-2026-75935 and CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service

    Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion da...

    Security notice Cybersecurity
  2. CVE-2026-85028: Creation of Temporary File in Directory with Insecure Permissions in AWS FPGA Development Kit

    Bulletin ID: 2026-096-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 11:00 AM PDT Description: The AWS FPGA Developer Kit is a hardware-software developmen...

    Security notice Cybersecurity 2 versions
  3. CVE-2026-85787 - An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server to modify data beyond the read-only scope

    Bulletin ID: 2026-101-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 13:00 PM PDT Description: We have identified CVE-2026-85787, an incomplete list of dis...

    Security notice Cybersecurity 2 versions
  4. CVE-2026-81849 - Path traversal in the aws:downloadContent plugin in amazon-ssm-agent

    Bulletin ID: 2026-091-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/28/2026 11:00 AM PDT Description: AWS Systems Manager Agent (amazon-ssm-agent) is Amazon softw...

    Security notice Cybersecurity 2 versions
  5. CVE-2026-81838 - Zip Slip path traversal in awsdac (diagram-as-code)

    Bulletin ID: 2026-090-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/27/2026 13:00 PM PDT awsdac (diagram-as-code) is a CLI tool that generates AWS architecture di...

    Security notice Cybersecurity 3 versions
  6. CVE-2026-18952 - Missing Input Validation in OpenSearch Security Analytics Plugin

    Bulletin ID: 2026-079-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:45 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...

    Security notice Cybersecurity 2 versions
  7. CVE-2026-85788 - Issue with awslabs mysql-mcp-server

    Bulletin ID: 2026-103-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/09/2026 09:30 AM PDT Description: We identified an issue in awslabs.mysql-mcp-server (an open-...

    Security notice Cybersecurity 2 versions
  8. CVE-2026-19111 - Insecure direct object reference in Strands Agents Tools memory tools

    Bulletin ID: 2026-077-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/06/2026 11:00 AM PDT Description: Strands Agents is an open-source SDK for building AI agents....

    Security notice Cybersecurity 2 versions
  9. CVE-2026-84851- Uncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6

    Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon I...

    Security notice Cybersecurity 2 versions
  10. CVE-2026-18428 - OpenSearch SQL Plugin - Async Query Validation Bypass

    Bulletin ID: 2026-081-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/13/2026 10:30 AM PDT Description: OpenSearch SQL plugin is a plugin that enables SQL and PPL q...

    Security notice Cybersecurity 2 versions
  11. CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver

    Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT Description: The Amazon EFS CSI Driver is an open-source Kubernetes Conta...

    Security notice Cybersecurity 2 versions
  12. Issue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-77237

    Bulletin ID: 2026-086-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 10:30 AM PDT Description: FreeRTOS-Kernel is a real-time operating system kernel for m...

    Security notice Cybersecurity 2 versions
  13. CVE-2026-85012 - OS command injection in the Amazon CodeCatalyst blueprints SDK

    Bulletin ID: 2026-095-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/03/2026 10:00 AM PDT Description: Amazon CodeCatalyst blueprints are reusable project template...

    Security notice Cybersecurity 2 versions
  14. CVE-2026-19311- Missing Authorization in OpenSearch Alerting Plugin

    Bulletin ID: 2026-078-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/12/2026 11:30 AM PDT Description: OpenSearch is a community-driven, open-source search and ana...

    Security notice Cybersecurity 2 versions

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.