What is CVE-2026-19642?
CVE-2026-19642 is an out-of-bounds write vulnerability in the Base64 decoder of Amazon aws-sdk-cpp prior to version 1.11.862. It may allow a remote authenticated user to cause a crash or heap memory corruption in applications processing crafted Base64-encoded input. Users should upgrade to version 1.11.862 or later to remediate the issue.
Azərbaycanca: CVE-2026-19642, Amazon aws-sdk-cpp kitabxanasının 1.11.862-dən əvvəlki versiyalarında Base64 dekoderində "out-of-bounds write" zəifliyidir. Bu, uzaqdan autentifikasiya olunmuş şəxsə xüsusi hazırlanmış Base64 girişi ilə tətbiqdə çökmə və ya "heap memory corruption" yaratmağa imkan verə bilər. Problemi həll etmək üçün 1.11.862 və ya daha yeni versiyaya yeniləmək tələb olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which versions of the Amazon aws-sdk-cpp library are affected by CVE-2026-19642?
CVE-2026-19642 affects versions of the Amazon aws-sdk-cpp library prior to 1.11.862.
What can a remote authenticated user achieve by exploiting CVE-2026-19642?
A remote authenticated user can cause a crash or heap memory corruption by providing crafted Base64-encoded input.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.