Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
References
Configurations
No configuration.
History
12 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
12 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 19:16
Updated : 2026-06-16 15:42
NVD link : CVE-2026-12043
Mitre link : CVE-2026-12043
CVE.ORG link : CVE-2026-12043
JSON object : View
Products Affected
No product.
CWE
CWE-415
Double Free
