CVE-2026-12043

Source
https://cve.org/CVERecord?id=CVE-2026-12043
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12043.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-12043
Aliases
  • GHSA-rmjr-3qpm-vh98
Published
2026-06-12T18:35:51.420Z
Modified
2026-08-12T15:31:16.217128Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Heap double-free in AWS Common Runtime aws-c-http
Details

Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.

To remediate this issue, users should upgrade to aws-c-http version 0.11.0.

Database specific
{
    "cwe_ids": [
        "CWE-415"
    ],
    "cna_assigner": "AMZN",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12043.json"
}
References

Affected packages

Git / github.com/awslabs/aws-c-http

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/aws-c-http
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0.4.22"
        },
        {
            "last_affected": "0.10.15"
        }
    ]
}

Affected versions

v0.*
v0.10.0
v0.10.1
v0.10.10
v0.10.11
v0.10.12
v0.10.13
v0.10.14
v0.10.15
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.4.22
v0.4.23
v0.4.24
v0.4.25
v0.4.26
v0.4.27
v0.4.28
v0.5.1
v0.5.10
v0.5.11
v0.5.12
v0.5.13
v0.5.14
v0.5.15
v0.5.16
v0.5.17
v0.5.18
v0.5.19
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9
v0.6.0
v0.6.1
v0.6.10
v0.6.11
v0.6.12
v0.6.13
v0.6.14
v0.6.15
v0.6.16
v0.6.17
v0.6.18
v0.6.19
v0.6.2
v0.6.20
v0.6.21
v0.6.22
v0.6.23
v0.6.24
v0.6.25
v0.6.26
v0.6.27
v0.6.28
v0.6.29
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.6.7
v0.6.8
v0.6.9
v0.7.0
v0.7.1
v0.7.10
v0.7.11
v0.7.12
v0.7.13
v0.7.14
v0.7.15
v0.7.2
v0.7.3
v0.7.4
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.7.9
v0.8.0
v0.8.1
v0.8.10
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12043.json"
vanir_signatures
[
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "96872287347827358514189847538865503800",
            "length": 1720.0
        },
        "target": {
            "function": "aws_hpack_insert_header",
            "file": "source/hpack.c"
        },
        "source": "https://github.com/awslabs/aws-c-http/commit/8aefd899fc3210bfd0e3fd414011a3cb708bf6e4",
        "signature_version": "v1",
        "id": "CVE-2026-12043-1e4611ee",
        "deprecated": false
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "124280645356525196712215732137927032157",
                "301642393092662340053319807357650229914",
                "165157777276860542560711956794670399568",
                "269278956214626889427380669948856080101",
                "181842221093139609251344321025937765665",
                "170262867104208531698686581472785423691",
                "280867948920478112109425199030879810598",
                "124492402619103279128665481606357510439"
            ]
        },
        "target": {
            "file": "source/hpack.c"
        },
        "source": "https://github.com/awslabs/aws-c-http/commit/8aefd899fc3210bfd0e3fd414011a3cb708bf6e4",
        "signature_version": "v1",
        "id": "CVE-2026-12043-8ae36b79",
        "deprecated": false
    }
]
vanir_signatures_modified
"2026-08-12T15:31:16Z"