Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
{
"cwe_ids": [
"CWE-415"
],
"cna_assigner": "AMZN",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12043.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12043.json"
[
{
"signature_type": "Function",
"digest": {
"function_hash": "96872287347827358514189847538865503800",
"length": 1720.0
},
"target": {
"function": "aws_hpack_insert_header",
"file": "source/hpack.c"
},
"source": "https://github.com/awslabs/aws-c-http/commit/8aefd899fc3210bfd0e3fd414011a3cb708bf6e4",
"signature_version": "v1",
"id": "CVE-2026-12043-1e4611ee",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"124280645356525196712215732137927032157",
"301642393092662340053319807357650229914",
"165157777276860542560711956794670399568",
"269278956214626889427380669948856080101",
"181842221093139609251344321025937765665",
"170262867104208531698686581472785423691",
"280867948920478112109425199030879810598",
"124492402619103279128665481606357510439"
]
},
"target": {
"file": "source/hpack.c"
},
"source": "https://github.com/awslabs/aws-c-http/commit/8aefd899fc3210bfd0e3fd414011a3cb708bf6e4",
"signature_version": "v1",
"id": "CVE-2026-12043-8ae36b79",
"deprecated": false
}
]
"2026-08-12T15:31:16Z"