CVE-2026-12043: Heap double-free in AWS Common Runtime aws-c-http
Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote threat actor operating a server to cause memory corruption on a connecting client application, potentially leading to arbitrary code execution, via a crafted sequence of HTTP/2 HEADERS frames.
To remediate this issue, users should upgrade to aws-c-http version 0.11.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aws-c-httpto a version that resolves this vulnerability.Fixed in 0.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12043?
CVE-2026-12043 has a severity rating of high, with a score of 8.8.
How do I fix CVE-2026-12043?
To fix CVE-2026-12043, update the AWS Common Runtime aws-c-http library to version 0.11.0 or later.
What type of vulnerability is CVE-2026-12043?
CVE-2026-12043 is classified as a double free vulnerability.
What can potentially be compromised due to CVE-2026-12043?
CVE-2026-12043 could potentially lead to arbitrary code execution on the connecting client application.
Who is affected by CVE-2026-12043?
Users utilizing the AWS Common Runtime aws-c-http library are at risk due to CVE-2026-12043.