Known Vulnerabilities for products from Amazon

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Amazon".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Amazon can be found at device.report : Amazon

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-89332 json Not Provided 2026-09-11 2026-09-11
CVE-2026-89090 json Not Provided 2026-09-11 2026-09-11
CVE-2026-89049 json Not Provided 2026-09-10 2026-09-10
CVE-2026-87912 json Not Provided 2026-09-10 2026-09-10
CVE-2026-87911 json Not Provided 2026-09-09 2026-09-10
CVE-2026-86175 json Not Provided 2026-09-05 2026-09-08
CVE-2026-85788 json Not Provided 2026-09-09 2026-09-09
CVE-2026-85787 json Not Provided 2026-09-04 2026-09-08
CVE-2026-85786 json Not Provided 2026-09-04 2026-09-04
CVE-2026-85781 json Not Provided 2026-09-04 2026-09-04
CVE-2026-81838 json A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through ... Not Provided 2026-08-27 2026-09-04
CVE-2026-77237 json Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task o... Not Provided 2026-08-21 2026-08-25
CVE-2026-77236 json Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corr... Not Provided 2026-08-21 2026-08-25
CVE-2026-77235 json Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users... Not Provided 2026-08-21 2026-08-27
CVE-2026-77234 json Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute c... Not Provided 2026-08-21 2026-08-27
CVE-2026-35562 json Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a th... Not Provided 2026-04-03 2026-07-24
CVE-2026-35561 json Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver bef... Not Provided 2026-04-03 2026-07-24
CVE-2026-35560 json Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 mi... Not Provided 2026-04-03 2026-07-24
CVE-2026-35559 json Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor... Not Provided 2026-04-03 2026-07-24
CVE-2026-35558 json Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 migh... Not Provided 2026-04-03 2026-07-24

Known software with vulnerabilities from Amazon

Type Vendor Product Version
ApplicationAmazonAmazon Freertos1.0.0
ApplicationAmazonAmazon Music6.1.5.1213
ApplicationAmazonAmazon Web Services Cloudformation Bootstrap-
ApplicationAmazonAmazon Web Services Freertos1.0.0
ApplicationAmazonAmazon Web Services Software Development Kit2.0.5
ApplicationAmazonAudible2.34.0
ApplicationAmazonAws-lambda0.0.1
ApplicationAmazonAws Command Line Interface-
Operating
System
AmazonAws Command Line Interface-
ApplicationAmazonAws Encryption Sdk-
ApplicationAmazonAws Javascript S3 Explorer1.0.0
ApplicationAmazonAws S3 Crypto Sdk-
ApplicationAmazonAws Sdk For Javascipt-
ApplicationAmazonAws Shared Configuration File Loader0.1.0
HardwareAmazonBlink Xt2 Sync Module-
Operating
System
AmazonBlink Xt2 Sync Module Firmware2.13.11
ApplicationAmazonCorretto11
ApplicationAmazonEc2 Api Tools Java Library-
ApplicationAmazonElastic Load Balancing Api Tools-
ApplicationAmazonFirecracker0.1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report