CVE-2026-14265

Source
https://cve.org/CVERecord?id=CVE-2026-14265
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14265.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14265
Aliases
  • GHSA-c5q4-97jw-jggh
Published
2026-07-01T19:34:02.095Z
Modified
2026-07-15T01:49:09.584056319Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
RCE via Deserialization in AWS Advanced JDBC Wrapper
Details

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned.

We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later.

Database specific
{
    "cwe_ids": [
        "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14265.json",
    "cna_assigner": "AMZN"
}
References

Affected packages

Git / github.com/aws/aws-advanced-jdbc-wrapper

Affected ranges

Type
GIT
Repo
https://github.com/aws/aws-advanced-jdbc-wrapper
Events
Database specific
{
    "cpe": "cpe:2.3:a:amazon:advanced_jdbc_wrapper:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "3.3.0"
        },
        {
            "last_affected": "4.0.0"
        },
        {
            "fixed": "4.0.1"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14265.json"