VendorsAmazonaws_software_development_kitall versions
Vulnerabilities

Amazon AWS Software Development Kit (SDK)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2022-4725
AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery
Published 2022-12-24 · Modified
9.8EPSS 0.007
CVE-2018-19981
Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated and/or authorized requests. Note that the attacker must have "root" privilege access to the Android filesystem in order to exploit this vulnerability (i.e. the device has been compromised, such as disabling or bypassing Android's fundamental security mechanisms).
Published 2019-04-04 · Modified
9.0EPSS 0.018
CVE-2023-51651
Potential URI resolution path traversal in the AWS SDK for PHP
Published 2023-12-22 · Modified
6.0EPSS 0.004
CVE-2026-19643
Out-of-bounds read in the Base64 decoder in Amazon aws-sdk-cpp on signed-char platforms
Published 2026-08-12 · Analyzed
6.0EPSS 0.003
CVE-2026-19642
Out-of-bounds write in the Base64 decoder in Amazon aws-sdk-cpp
Published 2026-08-12 · Analyzed
6.0EPSS 0.003
CVE-2022-2582
Exposure of unencrypted plaintext hash in github.com/aws/aws-sdk-go
Published 2022-12-27 · Modified
4.3EPSS 0.005