Amazon vulnerabilities
8 CVEs tracked
Amazon's recent reporting context is dominated by vulnerabilities in the 'Smithy-RS' framework and npm supply chain attacks. Key incidents include uncontrolled recursion in deserializers (CVE-2026-15957) and missing timeouts and connection limits in the default HTTP server path (CVE-2026-16756), both enabling denial of service. Concurrently, Amazon's threat intelligence team attributed the high-profile compromises of npm packages like 'debug' and 'chalk' to North Korean actors as a precursor to the 'axios' hack. Additionally, improper code generation in the 'codegen-ui-react' library poses a remote code execution risk (CVE-2026-18245). Defenders should focus on implementing network-level DoS protections for Smithy-based services, verifying the integrity of npm dependencies, and patching UI code generation tools.
Azərbaycanca: Amazon-un son hesabatlarında əsas diqqət mərkəzində "Smithy-RS" (AWS SDK for Rust) və "aws-smithy-http-server" çərçivələrindəki zəifliklər dayanır. CVE-2026-15957 deserializasiya zamanı idarəolunmaz rekursiya, CVE-2026-16756 isə defolt server konfiqurasiyasında timeout və bağlantı limitlərinin olmaması səbəbindən xidmət əleyhinə (DoS) hücumlarına şərait yaradır. Eyni zamanda, Amazon-un təhlükəsizlik komandası Şimali Koreya qrupuna aid edilən "npm" təchizat zənciri hücumlarını ("debug", "chalk" və "axios" paketləri) ifşa edib. Bundan əlavə, "codegen-ui-react" kitabxanasında ixtiyari kod icrasına yol aça bilən CVE-2026-18245 diqqət çəkir. Müdafiəçilər "Smithy" əsaslı servislərdə şəbəkə səviyyəsində DoS qorunmasına, "npm" asılılıqlarının bütövlüyünə və frontend kod generasiyası alətlərinin güncəllənməsinə önəm verməlidir.
This vendor's CVEs8
This hub is built from skopnix's own reporting on Amazon: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.