CVE-2026-35562

HIGH

Allocation of resources without limits in parsing components in Amazon Athena ODBC driver

Title source: cna
STIX 2.1

Description

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should upgrade to version 2.1.0.0.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 28.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (2)
Amazon/Amazon Athena ODBC driver 2.1.0.0
amazon/athena_odbc < 2.1.0.0
Published Apr 03, 2026
Tracked Since Apr 04, 2026