Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-10740 - Excessive memory allocation in s2n-quic

A security vulnerability in the AWS Cloud Development Kit (CDK) tool aws-cdk-lib allows a user who can control certain configuration properties to execute arbitrary operating system commands on the machine running the CDK toolchain. This could let an attacker run harmful commands if they control those property values.

QCS published 11/10/2026, 3:31:41 am ISTVendor disclosure 9/10/2026, 9:44:05 pm ISTVerified 11/10/2026, 3:31:41 am ISTRevision 1

In plain language

What this advisory means

A security vulnerability in the AWS Cloud Development Kit (CDK) tool aws-cdk-lib allows a user who can control certain configuration properties to execute arbitrary operating system commands on the machine running the CDK toolchain. This could let an attacker run harmful commands if they control those property values.

Technical explanation

How the issue affects the environment

CVE-2026-11417 is an OS command injection vulnerability in the NodejsFunction local bundling pipeline component of aws-cdk-lib before version 2.245.0 (and version 2.246.0 on Windows). An attacker capable of controlling values in bundling properties such as externalModules, define, loader, inject, or esbuildArgs can inject shell metacharacters that the bundler interprets, leading to arbitrary command execution on the host executing the CDK toolchain.

Operational impact

Why teams should care

If exploited, this vulnerability enables attackers to execute arbitrary commands on build systems running aws-cdk-lib, potentially compromising the environment where cloud infrastructure code is developed. This can result in unauthorized access, data compromise, or disruption of development workflows, affecting cloud infrastructure deployment and operations.

Immediate action

Upgrade aws-cdk-lib to version 2.245.0 or later (2.246.0 or later on Windows). Ensure any forked or derivative code includes these fixes to prevent the vulnerability from being exploited.

Affected and fixed releases

Affected versionsAll aws-cdk-lib versions before 2.245.0 (2.246.0 on Windows)
Fixed versions2.245.0 (2.246.0 on Windows) and later

Temporary risk reduction

Limit the values of NodejsFunction bundling properties (externalModules, define, loader, inject, esbuildArgs) to trusted sources only. Audit all third-party constructs and pull requests that set these properties to avoid injection of malicious commands.

Evidence and validation checklist

  • AWS Security Bulletin published 2026-10-09 confirming CVE-2026-11417 details
  • Description of OS command injection via NodejsFunction bundling properties in aws-cdk-lib
  • Affected versions specified as before 2.245.0 (2.246.0 on Windows)
  • Recommended upgrade versions given
  • Workaround advising controlled input for bundling properties

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source