CyberRota Analysis
AI-GeneratedThe Amazon AWS SDK for Go v2 prior to release-2026-03-23 is vulnerable to an unrecovered panic in the event stream header decoder, which could allow an unauthenticated remote attacker to crash the consuming application by sending a specially crafted event stream response frame. Organizations using this SDK should prioritize upgrading to the specified release to mitigate the risk of application termination. Additionally, any forked or derivative code must also be patched to ensure security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code.