← Back

Amazon

amazon

198 CVEs • 107 products

Products (107)

Click to collapse
Toggle
Freertos
freertos
Fire Os
fire_os
Opensearch
opensearch
Tough
tough
Athena Odbc
athena_odbc
Firecracker
firecracker
Data.all
data.all
Aws Lc Sys
aws-lc-sys
Aws Libcrypto
aws_libcrypto
Kiro Ide
kiro_ide
Tuftool
tuftool
Kindle Touch
kindle_touch
Kindle For Pc
kindle_for_pc
Audible
audible
Workspaces
workspaces
Log4jhotpatch
log4jhotpatch
Amazon Linux
amazon_linux
Kiro Cli
kiro_cli
Merchant Sdk
merchant_sdk
Kindle
kindle
Amazon Music
amazon_music
Echo Firmware
echo_firmware
Freertos+fat
freertos+fat
Aws Lambda
aws_lambda
Open Distro
open_distro
Aws Workspaces
aws_workspaces
Sockeye
sockeye
Aws Opensearch
aws_opensearch
Hotpatch
hotpatch
Aws Sdk Java
aws-sdk-java
Efs Utils
efs-utils
Aws Sigv4
aws-sigv4
Alexa
alexa
Aws Dataall
aws-dataall
Ion
ion
Amplify Cli
amplify_cli
Harmonix
harmonix
Aurora Mysql
aurora_mysql
Efs Csi Driver
efs_csi_driver
Cloudfront
cloudfront
S3 Store
s3_store
Sdk Tester
sdk_tester
Amazon Key
amazon_key
Echo Show
echo_show
Echo Plus
echo_plus
Echo Dot
echo_dot
Echo Spot
echo_spot

CVEs (198)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amazon
1Aws Api Mcp Server
Jun 17, 2026
Mar 16, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and exp...Show more
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.Show less
2Amazon
Mariadb
3Aurora Mysql
MariadbRelational Database Service
Jul 14, 2026
Mar 3, 2026
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQ...Show more
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.Show less
2Amazon
Aws
3Aws Lc Sys
Aws LibcryptoAws Libcrypto
Jul 15, 2026
Mar 2, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not n...Show more
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.Show less
2Amazon
Aws
4Aws Lc Fips Sys
Aws Lc SysAws Libcrypto+1 more
Jun 17, 2026
Mar 2, 2026
8.2 HIGH· v4
5.9 MEDIUM· v3
N/A· v2
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP...Show more
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.Show less
2Amazon
Aws
3Aws Lc Sys
Aws LibcryptoAws Libcrypto
Jul 15, 2026
Mar 2, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers...Show more
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.Show less
1Amazon
1Firecracker
Jun 17, 2026
Jan 23, 2026
6.0 MEDIUM· v4
6.0 MEDIUM· v3
N/A· v2
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrit...Show more
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.Show less
1Amazon
1Kiro Ide
Jun 17, 2026
Jan 9, 2026
8.4 HIGH· v4
7.8 HIGH· v3
N/A· v2
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To m...Show more
Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.Show less
1Amazon
1Harmonix
Jun 17, 2026
Dec 15, 2025
8.6 HIGH· v4
7.2 HIGH· v3
N/A· v2
An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning rol...Show more
An overly-permissive IAM trust policy in the Harmonix on AWS framework may allow IAM principals in the same AWS account to escalate privileges via role assumption. The sample code for the EKS environment provisioning role is configured to trust the account root principal, which may enable any IAM principal in the same AWS account with sts:AssumeRole permissions to assume the role with administrative privileges. We recommend customers upgrade to Harmonix on AWS v0.4.2 or later if you have deployed the framework using versions v0.3.0 through v0.4.1.Show less
1Amazon
1Opensearch
Jun 17, 2026
Nov 25, 2025
8.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
1Amazon
1Opensearch Data Prepper
Jun 17, 2026
Oct 15, 2025
N/A· v4
7.4 HIGH· v3
N/A· v2
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certifica...Show more
OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when connecting to OpenSearch clusters if no certificate path was explicitly configured. This behavior bypasses SSL certificate validation, potentially allowing attackers to intercept and modify data in transit through man-in-the-middle attacks. The vulnerability affects connections to OpenSearch when the cert parameter is not explicitly provided. This issue has been patched in version 2.12.2. As a workaround, users can add the cert parameter to their OpenSearch sink or source configuration with the path to the cluster's CA certificate.Show less
1Amazon
1Freertos Plus Tcp
Jun 17, 2026
Oct 10, 2025
5.3 MEDIUM· v4
4.3 MEDIUM· v3
N/A· v2
A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This...Show more
A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects applications using IPv6. We recommend upgrading to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Freertos Plus Tcp
Jun 17, 2026
Oct 10, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects ap...Show more
A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6. We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Freertos Plus Tcp
Jun 17, 2026
Oct 10, 2025
5.3 MEDIUM· v4
5.4 MEDIUM· v3
N/A· v2
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These iss...Show more
A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6. Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Tough
Jun 17, 2026
Mar 27, 2025
5.7 MEDIUM· v4
4.5 MEDIUM· v3
N/A· v2
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next...Show more
During a snapshot rollback, the client incorrectly caches the timestamp metadata. If the client checks the cache when attempting to perform the next update, the update timestamp validation will fail, preventing the next update until the cache is cleared. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Tough
Jun 17, 2026
Mar 27, 2025
5.7 MEDIUM· v4
4.5 MEDIUM· v3
N/A· v2
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough...Show more
During a target rollback, the client fails to detect the rollback for delegated targets. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Tough
Jun 17, 2026
Mar 27, 2025
5.7 MEDIUM· v4
4.5 MEDIUM· v3
N/A· v2
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incor...Show more
Missing validation of terminating delegation causes the client to continue searching the defined delegation list, even after searching a terminating delegation. This could cause the client to fetch a target from an incorrect source, altering the target contents. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Tough
Jun 17, 2026
Mar 27, 2025
5.7 MEDIUM· v4
4.5 MEDIUM· v3
N/A· v2
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by...Show more
Missing validation of the root metatdata version number could allow an actor to supply an arbitrary version number to the client instead of the intended version in the root metadata file, altering the version fetched by the client. Users should upgrade to tough version 0.20.0 or later and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Aws Cloud Development Kit
Jun 17, 2026
Mar 21, 2025
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to t...Show more
When the AWS Cloud Development Kit (AWS CDK) Command Line Interface (AWS CDK CLI) is used with a credential plugin which returns an expiration property with the retrieved AWS credentials, the credentials are printed to the console output. To mitigate this issue, users should upgrade to version 2.178.2 or later and ensure any forked or derivative code is patched to incorporate the new fixes.Show less
1Amazon
1Aws Cloud Development Kit
Jun 17, 2026
Jan 17, 2025
1.8 LOW· v4
8.1 HIGH· v3
N/A· v2
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider...Show more
The AWS Cloud Development Kit (AWS CDK) is an open-source software development framework to define cloud infrastructure in code and provision it through AWS CloudFormation. Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow. However, the current `tls.connect` method will always set `rejectUnauthorized: false` which is a potential security concern. CDK should follow the best practice and set `rejectUnauthorized: true`. However, this could be a breaking change for existing CDK applications and we should fix this with a feature flag. Note that this is marked as low severity Security advisory because the issuer url is provided by CDK users who define the CDK application. If they insist on connecting to a unauthorized OIDC provider, CDK should not disallow this. Additionally, the code block is run in a Lambda environment which mitigate the MITM attack. The patch is in progress. To mitigate, upgrade to CDK v2.177.0 (Expected release date 2025-02-22). Once upgraded, users should make sure the feature flag '@aws-cdk/aws-iam:oidcRejectUnauthorizedConnections' is set to true in `cdk.context.json` or `cdk.json`. There are no known workarounds for this vulnerability.Show less
1Amazon
1Redshift Odbc Driver
Jun 17, 2026
Dec 24, 2024
8.6 HIGH· v4
8.0 HIGH· v3
N/A· v2
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver vers...Show more
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.Show less