CVE-2026-19643
An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input. To remediate this issue, users should upgrade to version 1.11.862.
- Published Aug 12, 2026
- CVSS 6.0 medium
- 0.6% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ AWS Security Bulletins ·