Metrics
Affected Vendors & Products
Fri, 12 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0. | |
| Title | Heap double-free in AWS Common Runtime aws-c-http | |
| First Time appeared |
Aws
Aws aws-c-http |
|
| Weaknesses | CWE-415 | |
| CPEs | cpe:2.3:a:aws:aws-c-http:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws-c-http |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-06-12T18:49:54.683Z
Reserved: 2026-06-11T19:50:48.263Z
Link: CVE-2026-12043
Updated: 2026-06-12T18:49:51.582Z
Status : Received
Published: 2026-06-12T19:16:26.420
Modified: 2026-06-12T19:16:26.420
Link: CVE-2026-12043
No data.
OpenCVE Enrichment
Updated: 2026-06-12T19:30:31Z