CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 11:15 PM PDT
Description:
AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded...
https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/
#aws #security
Remote
AWS Security Bulletins
@awssecurityfeed@infosec.exchange
Unofficial AWS Security Announcement Feed, run by @kjake@defcon.social
90 Followers
0 Following
4 Posts
Joined November 09, 2024
Open post
CVE-2026-15895: OS command injection in jsii-diff in AWS jsii
Bulletin ID: 2026-057-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/15/2026 12:00 PM PDT
Description:
jsii-diff is a command line tool to compare the API differences between two jsii assemblies...
https://aws.amazon.com/security/security-bulletins/rss/2026-057-aws/
#aws #security
0
0
0
0
Open post
CVE-2026-85781 - Unverified access point ownership in Amazon EFS CSI Driver
Bulletin ID: 2026-099-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/04/2026 11:45 AM PDT
Description:
The Amazon EFS CSI Driver is an open-source Kubernetes Container Storage Interface (CSI) dr...
https://aws.amazon.com/security/security-bulletins/rss/2026-099-aws/
#aws #security
0
0
0
0
Open post
CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
Bulletin ID: 2026-110-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/11/2026 10:00 AM PDT
Description:
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versio...
https://aws.amazon.com/security/security-bulletins/rss/2026-110-aws/
#aws #security
0
0
0
0