CVE-2026-35559

MEDIUM

Out-of-bounds write in query processing components in Amazon Athena ODBC driver

Title source: cna
STIX 2.1

Description

Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
Amazon/Amazon Athena ODBC driver 2.1.0.0
amazon/athena_odbc < 2.1.0.0
Published Apr 03, 2026
Tracked Since Apr 04, 2026