GHSA-xmrv-pmrh-hhx2
Dashboard / Vulnerabilities / GHSA-xmrv-pmrh-hhx2
Summary: Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
Details: **CVSSv3.1 Rating**: [Medium] **CVSSv3.1 Score**: [5.9] **CVSSv3.1 Vector String**: [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H] ## Summary and Impact An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23). An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) ## Patches This issue has been addressed in versions [2026-03-23](https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23) and above. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. ## Workarounds Not Applicable ## References If you have any questions or comments about this advisory, we ask that you contact [AWS/Amazon] Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.
References: https://github.com/aws/aws-sdk-go-v2/security/advisories/GHSA-xmrv-pmrh-hhx2, https://github.com/aws/aws-sdk-go-v2, https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23
Affected packages
Package
Name: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
Purl: pkg:golang/github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
Affected ranges
Type: SEMVER
Events:
