CVE-2026-12043
Severity CVSS v4.0:
HIGH
Type:
CWE-415
Double Free
Publication date:
12/06/2026
Last modified:
12/06/2026
Description
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
8.80
Severity 3.x
HIGH



