In plain language
What this advisory means
A security problem in the AWS Common Runtime's HTTP client library (aws-c-http) allows a remote attacker controlling a server to corrupt memory in a client application, possibly letting them execute arbitrary code. This happens when the client processes a specially crafted sequence of HTTP/2 HEADERS frames.
Technical explanation
How the issue affects the environment
The vulnerability CVE-2026-12043 is a heap double-free issue in the aws-c-http library, which handles HTTP requests for AWS SDKs. It arises from improper handling of HPACK dynamic table size updates when processing HTTP/2 HEADERS frames sent by a server. This flaw can lead to memory corruption in client applications using vulnerable versions of aws-c-http, potentially enabling remote arbitrary code execution.
Operational impact
Why teams should care
If exploited, this vulnerability could allow an attacker controlling a malicious server to execute arbitrary code on client applications using the affected AWS SDKs, risking compromise of those clients and any data they handle. Organizations depending on these SDKs for communication with AWS services might face security breaches or system takeovers.
Immediate action
Upgrade the aws-c-http library to version 0.11.0 or later. Also ensure any forked or derivative code based on this library is patched to incorporate the fix. Confirm that AWS SDKs are updated to versions using the fixed aws-c-http.
Affected and fixed releases
Temporary risk reduction
Configure client applications to use HTTP/1.1 connections instead of HTTP/2 if this option is available, to avoid triggering the vulnerability.
Evidence and validation checklist
- AWS Security Bulletins official advisory 2026-043-AWS
- CVE identifier CVE-2026-12043
- Description of heap double-free in aws-c-http due to HPACK dynamic table size updates
- Versions affected and fixed version 0.11.0 noted
- Recommendations for upgrade and HTTP/1.1 workaround
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
