Vulnerability Report: GO-2026-5764
- GHSA-xmrv-pmrh-hhx2
- Affects: github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream, github.com/aws/aws-sdk-go-v2/service/bedrockagentcore, and 10 more
- Published: Jul 07, 2026
DoS due to Panic in AWS SDK for Go v2 SDK EventStream Decoder in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
For detailed information about this vulnerability, visit https://github.com/aws/aws-sdk-go-v2/security/advisories/GHSA-xmrv-pmrh-hhx2.
Affected Modules
-
PathGo Versions
-
before v1.7.8
-
before v1.15.2
-
before v1.51.8
-
before v1.50.4
-
before v1.65.0
-
before v1.52.19
-
before v1.43.5
-
before v1.88.5
-
before v1.35.15
-
before v1.97.3
-
before v1.39.6
-
before v1.34.5
Aliases
References
- https://github.com/aws/aws-sdk-go-v2/security/advisories/GHSA-xmrv-pmrh-hhx2
- https://github.com/aws/aws-sdk-go-v2/releases/tag/release-2026-03-23
- https://vuln.go.dev/ID/GO-2026-5764.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.