{"id":"CVE-2026-5190","summary":"AWS C Event Stream Streaming Decoder Stack Buffer Overflow","details":"Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.\n\nTo remediate this issue, users should upgrade to version 0.6.0 or later.","aliases":["GHSA-xvjw-fjq5-68hf"],"modified":"2026-08-12T16:25:41.689905Z","published":"2026-03-31T17:05:59.601Z","related":["openSUSE-SU-2026:10512-1","openSUSE-SU-2026:20477-1"],"database_specific":{"cna_assigner":"AMZN","cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5190.json"},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-011-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5190.json"},{"type":"ADVISORY","url":"https://github.com/awslabs/aws-c-event-stream/security/advisories/GHSA-xvjw-fjq5-68hf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5190"},{"type":"FIX","url":"https://github.com/awslabs/aws-c-event-stream/releases/tag/v0.6.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/awslabs/aws-c-event-stream","events":[{"introduced":"0"},{"fixed":"c741f95e9050a1a4bed4b3aa7543bd3e024f6e56"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.6.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v0.5.9","v0.5.8","v0.5.7","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5.0","v0.4.3","v0.4.2","v0.4.1","v0.4.0","v0.3.2","v0.3.1","v0.3.0","v0.2.20","v0.2.19","v0.2.18","v0.2.17","v0.2.16","v0.2.15","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9","v0.2.7","v0.2.8","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5190.json","vanir_signatures_modified":"2026-08-12T16:25:41Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56","target":{"function":"aws_event_stream_read_headers_from_buffer","file":"source/event_stream.c"},"deprecated":false,"digest":{"function_hash":"199647504886363381172400436745317376772","length":2834},"id":"CVE-2026-5190-117481f3"},{"target":{"file":"source/event_stream.c","function":"s_read_header_value_len"},"deprecated":false,"digest":{"function_hash":"113509395165402558559469483209602666863","length":812},"id":"CVE-2026-5190-659b0901","signature_type":"Function","signature_version":"v1","source":"https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56","target":{"file":"source/event_stream.c","function":"aws_event_stream_add_bytebuf_header"},"deprecated":false,"digest":{"function_hash":"279575890830763744390095660858468072042","length":619},"id":"CVE-2026-5190-9ff1e532"},{"source":"https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56","target":{"file":"source/event_stream.c","function":"aws_event_stream_add_string_header"},"deprecated":false,"digest":{"function_hash":"152445393234969787399608675840878072267","length":614},"id":"CVE-2026-5190-c427746f","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/awslabs/aws-c-event-stream/commit/c741f95e9050a1a4bed4b3aa7543bd3e024f6e56","target":{"file":"source/event_stream.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["190359577887961147690961769086736590717","280213090956888536344605713956804050425","172069340247330824382542074650193528408","203385997535759877460935544809994347168","307664894495085905813960114133291151071","51889819453309621849428525944066138164","142454392195604595851343029243921044258","158537315449147736780364422440091455809","157522428878403230363637731700287907836","279300541627149573544605942359639020287","181492100720604595698638188214191814980","97123695277323062826021099877615414851","158537315449147736780364422440091455809","157522428878403230363637731700287907836","122257163225009955527265868392526855909","335105134054129640726992357583245893570","245263496762550442100223179311608319043","110206413172342877373236557849161708128"]},"id":"CVE-2026-5190-e27d23f5","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}