Amazon
First CVE: Oct 22, 2024Active for: 2 years
127
CVEs Published
More CVEs Published than 73% of tracked CNAs
42.3
Avg CVEs / Year
More Avg CVEs / Year than 82% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Amazon as a CNA, 43.3% affect products that Amazon develops as a vendor.
43.3%
56.7%
Self-reported: 55Third-party: 72
Of all the CVEs published that affect products developed by Amazon, 28.2% are self-published by Amazon as a CNA.
28.2%
71.8%
Self-published: 55Published by other CNAs: 140
Trends Over Time
The number and severity of CVEs published by Amazon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2024
21 months ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Amazon as a CNA, regardless of affected vendor or product.
127 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13763CRITICAL Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via cr | Jun 29, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-13762CRITICAL Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 | Jun 29, 2026 | 9.8 | 43 | NO | NO |
CVE-2025-0851CRITICAL A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations. | Jan 29, 2025 | 9.8 | 43 | NO | NO |
CVE-2026-12957HIGH Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a m | Jun 23, 2026 | 7.8 | 42 | NO | NO |
CVE-2026-8838CRITICAL Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to | May 18, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-14265HIGH Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the s | Jul 1, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-12958HIGH Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace | Jun 23, 2026 | 7.8 | 37 | NO | NO |
CVE-2026-11393CRITICAL Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitra | Jun 8, 2026 | 9.0 | 37 | NO | NO |
CVE-2026-10591HIGH Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remote unauthenticated actors to execute arbitrary commands via c | Jun 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-6911CRITICAL Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the | Apr 24, 2026 | 9.8 | 37 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA127 CVEs
43%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local27 (21.3%)
Network94 (74.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network6 (4.7%)
Attack Complexity
Low101 (79.5%)
High26 (20.5%)
Unknown0 (0.0%)
User Interaction
None86 (67.7%)
Unknown0 (0.0%)
Required41 (32.3%)
Privileges Required
Low53 (41.7%)
High15 (11.8%)
None59 (46.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (127 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Amazon as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Amazon as a CNA — matched by CVE ID, not by organization name.