CVE-2026-5190

Source
https://cve.org/CVERecord?id=CVE-2026-5190
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5190.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5190
Aliases
  • GHSA-xvjw-fjq5-68hf
Downstream
Related
Published
2026-03-31T17:05:59.601Z
Modified
2026-08-12T16:25:41.689905Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
AWS C Event Stream Streaming Decoder Stack Buffer Overflow
Details

Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.

To remediate this issue, users should upgrade to version 0.6.0 or later.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-787"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5190.json"
}
References

Affected packages

Git / github.com/awslabs/aws-c-event-stream

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/aws-c-event-stream
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.6.0"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.2.1
v0.2.10
v0.2.11
v0.2.12
v0.2.13
v0.2.14
v0.2.15
v0.2.16
v0.2.17
v0.2.18
v0.2.19
v0.2.2
v0.2.20
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9
v0.3.0
v0.3.1
v0.3.2
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9

Database specific

vanir_signatures_modified
"2026-08-12T16:25:41Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5190.json"
vanir_signatures
[
    {
        "deprecated": false,
        "target": {
            "function": "aws_event_stream_read_headers_from_buffer",
            "file": "source/event_stream.c"
        },
        "signature_type": "Function",
        "source": "https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56",
        "digest": {
            "length": 2834.0,
            "function_hash": "199647504886363381172400436745317376772"
        },
        "signature_version": "v1",
        "id": "CVE-2026-5190-117481f3"
    },
    {
        "deprecated": false,
        "target": {
            "function": "s_read_header_value_len",
            "file": "source/event_stream.c"
        },
        "signature_type": "Function",
        "source": "https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56",
        "digest": {
            "length": 812.0,
            "function_hash": "113509395165402558559469483209602666863"
        },
        "signature_version": "v1",
        "id": "CVE-2026-5190-659b0901"
    },
    {
        "deprecated": false,
        "target": {
            "function": "aws_event_stream_add_bytebuf_header",
            "file": "source/event_stream.c"
        },
        "signature_type": "Function",
        "source": "https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56",
        "digest": {
            "length": 619.0,
            "function_hash": "279575890830763744390095660858468072042"
        },
        "signature_version": "v1",
        "id": "CVE-2026-5190-9ff1e532"
    },
    {
        "deprecated": false,
        "target": {
            "function": "aws_event_stream_add_string_header",
            "file": "source/event_stream.c"
        },
        "signature_type": "Function",
        "source": "https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56",
        "digest": {
            "length": 614.0,
            "function_hash": "152445393234969787399608675840878072267"
        },
        "signature_version": "v1",
        "id": "CVE-2026-5190-c427746f"
    },
    {
        "deprecated": false,
        "target": {
            "file": "source/event_stream.c"
        },
        "signature_type": "Line",
        "source": "https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56",
        "digest": {
            "line_hashes": [
                "190359577887961147690961769086736590717",
                "280213090956888536344605713956804050425",
                "172069340247330824382542074650193528408",
                "203385997535759877460935544809994347168",
                "307664894495085905813960114133291151071",
                "51889819453309621849428525944066138164",
                "142454392195604595851343029243921044258",
                "158537315449147736780364422440091455809",
                "157522428878403230363637731700287907836",
                "279300541627149573544605942359639020287",
                "181492100720604595698638188214191814980",
                "97123695277323062826021099877615414851",
                "158537315449147736780364422440091455809",
                "157522428878403230363637731700287907836",
                "122257163225009955527265868392526855909",
                "335105134054129640726992357583245893570",
                "245263496762550442100223179311608319043",
                "110206413172342877373236557849161708128"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2026-5190-e27d23f5"
    }
]