CVE-2026-5190EPSS p42.9%
CVE-2026-5190CVE-2026-5190
Description
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0.6.0 might allow a third party operating a server to cause memory corruption leading to arbitrary code execution on a client application that processes crafted event-stream messages.
To remediate this issue, users should upgrade to version 0.6.0 or later.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.53% probability of exploitation · percentile 42.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-24 |