AWS Latest Bulletins
Follow
CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
AWS has issued an important bulletin regarding critical vulnerabilities in the AWS SDK for C++. Two specific CVEs, CVE-2026-19642 and CVE-2026-19643, affect the Base64 decoder within the SDK. CVE-2026-19642 describes an out-of-bounds write vulnerability. This could lead to memory corruption or application crashes. CVE-2026-19643 details an out-of-bounds read vulnerability. On certain platforms, this could also result in application crashes. The impact of both these vulnerabilities is limited to the specific process performing the Base64 decoding. All versions of the AWS SDK for C++ up to and including version 1.11.861 are affected. AWS strongly advises users to address these issues promptly. Further details and the most current information can be found in the linked article.