Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http

A security problem in the AWS Common Runtime's HTTP client library (aws-c-http) allows a remote attacker controlling a server to corrupt memory in a client application, possibly letting them execute arbitrary code. This happens when the client processes a specially crafted sequence of HTTP/2 HEADERS frames.

QCS published 11/10/2026, 12:19:41 am ISTVendor disclosure 9/10/2026, 9:44:05 pm ISTVerified 11/10/2026, 3:31:22 am ISTRevision 1

In plain language

What this advisory means

A security problem in the AWS Common Runtime's HTTP client library (aws-c-http) allows a remote attacker controlling a server to corrupt memory in a client application, possibly letting them execute arbitrary code. This happens when the client processes a specially crafted sequence of HTTP/2 HEADERS frames.

Technical explanation

How the issue affects the environment

The vulnerability CVE-2026-12043 is a heap double-free issue in the aws-c-http library, which handles HTTP requests for AWS SDKs. It arises from improper handling of HPACK dynamic table size updates when processing HTTP/2 HEADERS frames sent by a server. This flaw can lead to memory corruption in client applications using vulnerable versions of aws-c-http, potentially enabling remote arbitrary code execution.

Operational impact

Why teams should care

If exploited, this vulnerability could allow an attacker controlling a malicious server to execute arbitrary code on client applications using the affected AWS SDKs, risking compromise of those clients and any data they handle. Organizations depending on these SDKs for communication with AWS services might face security breaches or system takeovers.

Immediate action

Upgrade the aws-c-http library to version 0.11.0 or later. Also ensure any forked or derivative code based on this library is patched to incorporate the fix. Confirm that AWS SDKs are updated to versions using the fixed aws-c-http.

Affected and fixed releases

Affected versionsaws-c-http version 0.4.22 and later until before 0.11.0, aws-sdk-cpp version 1.11.41 and later, aws-sdk-java-v2 version 2.44.27 and later
Fixed versionsaws-c-http version 0.11.0

Temporary risk reduction

Configure client applications to use HTTP/1.1 connections instead of HTTP/2 if this option is available, to avoid triggering the vulnerability.

Evidence and validation checklist

  • AWS Security Bulletins official advisory 2026-043-AWS
  • CVE identifier CVE-2026-12043
  • Description of heap double-free in aws-c-http due to HPACK dynamic table size updates
  • Versions affected and fixed version 0.11.0 noted
  • Recommendations for upgrade and HTTP/1.1 workaround

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source