CVE Explorer
CVE-2026-22611
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"aws-sdk-net","vendor":"aws","versions":[{"status":"affected","version":">= 4.0.0, < 4.0.3.3"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:158aa75588aee594136a446c5ad0e8ec449facf3658cb2e36e8ab529f96be05b · sha256:18cd24325a4c1508… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:158aa75588aee594136a446c5ad0e8ec449facf3658cb2e36e8ab529f96be05b · sha256:18cd24325a4c1508… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:158aa75588aee594136a446c5ad0e8ec449facf3658cb2e36e8ab529f96be05b · sha256:18cd24325a4c1508… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/aws/aws-sdk-net/security/advisories/GHSA-9cvc-h2w8-phrp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/aws/aws-sdk-net/security/advisories/GHSA-9cvc-h2w8-phrp"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:158aa75588aee594136a446c5ad0e8ec449facf3658cb2e36e8ab529f96be05b · sha256:18cd24325a4c1508… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.