CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2

Published 2026-09-11T17:09:09Z6a0d0961aea9da661e9b1e61f263475268f7eab22db4580b62c3b823525194fd

Source metadata

Publication date
2026-09-11T17:09:09Z
Source identifier
fcb543a35cb39751806398f87b68941193545749
Public record ID
record:sha256:6a0d0961aea9da661e9b1e61f263475268f7eab22db4580b62c3b823525194fd

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
6a0d0961aea9da661e9b1e61f263475268f7eab22db4580b62c3b823525194fd
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2 · Baitaphish