
AWS patched two memory-safety flaws in the AWS SDK for C++ Base64 decoder. CVE-2026-19642 is an out-of-bounds write, CVE-2026-19643 an out-of-bounds read, both from crafted input, no RCE demonstrated. Fixed in SDK 1.11.862 by delegating to the AWS Common Runtime. Vendored or statically-linked builds must update the aws-crt-cpp submodule too, no workaround exists.
Post summary
AWS released patches for two memory‑safety bugs in the C++ SDK Base64 decoder, with no evidence of exploitation or PoC.

