{"id":"OESA-2026-3687","summary":"aws-sdk-cpp security update","details":"The AWS SDK for C++ provides a modern C++ (version C++ 11 or later) interface  for Amazon Web Services (AWS). This package contains the S3 component.\r\n\r\nSecurity Fix(es):\n\nMissing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an &quot;instruction file&quot; instead of S3&apos;s metadata record.\n\nTo mitigate this issue, upgrade AWS SDK for C++ to version 1.11.712 or later(CVE-2025-14760)\n\nAn out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input.\n\n\n\nTo remediate this issue, users should upgrade to version 1.11.862.(CVE-2026-19642)\n\nAn out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input.\n\n\n\nTo remediate this issue, users should upgrade to version 1.11.862.(CVE-2026-19643)","modified":"2026-09-05T15:16:37.127369758Z","published":"2026-09-05T15:03:56Z","upstream":["CVE-2025-14760","CVE-2026-19642","CVE-2026-19643"],"database_specific":{"severity":"Medium"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3687"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14760"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19642"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19643"}],"affected":[{"package":{"name":"aws-sdk-cpp","ecosystem":"openEuler:22.03-LTS-SP4","purl":"pkg:rpm/openEuler/aws-sdk-cpp&distro=openEuler-22.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.327-4.oe2203sp4"}]}],"ecosystem_specific":{"aarch64":["aws-sdk-cpp-1.11.327-4.oe2203sp4.aarch64.rpm","aws-sdk-cpp-debuginfo-1.11.327-4.oe2203sp4.aarch64.rpm","aws-sdk-cpp-debugsource-1.11.327-4.oe2203sp4.aarch64.rpm","aws-sdk-cpp-devel-1.11.327-4.oe2203sp4.aarch64.rpm"],"src":["aws-sdk-cpp-1.11.327-4.oe2203sp4.src.rpm"],"x86_64":["aws-sdk-cpp-1.11.327-4.oe2203sp4.x86_64.rpm","aws-sdk-cpp-debuginfo-1.11.327-4.oe2203sp4.x86_64.rpm","aws-sdk-cpp-debugsource-1.11.327-4.oe2203sp4.x86_64.rpm","aws-sdk-cpp-devel-1.11.327-4.oe2203sp4.x86_64.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3687.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}