CVE-2026-35562

Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should upgrade to version 2.1.0.0.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) La asignación de recursos sin límites en los componentes de análisis del controlador ODBC de Amazon Athena anterior a la versión 2.1.0.0 podría permitir a un actor de amenazas causar una denegación de servicio al entregar una entrada especialmente diseñada que desencadena un consumo excesivo de recursos durante las operaciones de análisis del controlador. Para remediar este problema, los usuarios deberían actualizar a la versión 2.1.0.0.

14 Apr 2026, 16:14

Type Values Removed Values Added
First Time Microsoft
Linux linux Kernel
Amazon
Linux
Microsoft windows
Apple macos
Apple
Amazon athena Odbc
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
References () https://aws.amazon.com/security/security-bulletins/2026-013-aws/ - () https://aws.amazon.com/security/security-bulletins/2026-013-aws/ - Vendor Advisory
References () https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html - () https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html - Release Notes
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm - Patch
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg - Patch
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg - Patch
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi - Patch

03 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 21:17

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35562

Mitre link : CVE-2026-35562

CVE.ORG link : CVE-2026-35562


JSON object : View

Products Affected

amazon

  • athena_odbc

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-770

Allocation of Resources Without Limits or Throttling