CVE-2026-12043
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames. To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
- Published Jun 12, 2026
- CVSS 8.7 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http AWS Security Bulletins ·