
AWS patched two memory-safety flaws in the AWS SDK for C++ Base64 decoder. CVE-2026-19642 is an out-of-bounds write, CVE-2026-19643 an out-of-bounds read, both from crafted input, no RCE demonstrated. Fixed in SDK 1.11.862 by delegating to the AWS Common Runtime. Vendored or statically-linked builds must update the aws-crt-cpp submodule too, no workaround exists.
Post summary
AWS released patches for CVE-2026-19642 and CVE-2026-19643, addressing out‑of‑bounds write and read in the AWS SDK for C++ Base64 decoder. The updates are bundled in SDK 1.11.862 and require updating the aws-crt-cpp submodule for vendored or static builds.

