aws.amazon.comVendor advisory
https://aws.amazon.com/security/security-bulletins/2026-080-aws CVE-2026-19643
MEDIUM
Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms
Record summary
CVE-2026-19643 has a selected CVSS score of 6.0 (medium).
Description
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
aws-sdk-cppBrowse AWS / aws-sdk-cppDefault status: unaffected | CVE List | Through 1.11.861 | affected |
References
3github.comrelease notespatch
https://github.com/aws/aws-sdk-cpp/releases/tag/1.11.862 github.comrelease notes
https://github.com/aws/aws-sdk-cpp/security/advisories/GHSA-mxm9-xpf9-x66x