CVE-2026-12043
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-415
Doble liberación
Fecha de publicación:
12/06/2026
Última modificación:
12/06/2026
Descripción
*** Pendiente de traducción *** Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.<br />
<br />
<br />
<br />
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
Impacto
Puntuación base 4.0
8.70
Gravedad 4.0
ALTA
Puntuación base 3.x
8.80
Gravedad 3.x
ALTA



