CVE-2026-35562: Allocation of resources without limits in parsing components in Amazon Athena ODBC driver
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations.
To remediate this issue, users should upgrade to version 2.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driverto a version that resolves this vulnerability.Fixed in 2.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35562?
CVE-2026-35562 is classified as a high severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2026-35562?
To mitigate CVE-2026-35562, upgrade to Amazon Athena ODBC driver version 2.1.0.0 or later.
What software is affected by CVE-2026-35562?
CVE-2026-35562 affects versions of the Amazon Athena ODBC driver prior to 2.1.0.0.
What type of attack can exploit CVE-2026-35562?
CVE-2026-35562 can be exploited by delivering crafted input that triggers resource allocation issues, leading to denial of service.
Is there a known workaround for CVE-2026-35562?
There are no documented workarounds for CVE-2026-35562; updating the software is the recommended action.