GHSA-xmrv-pmrh-hhx2: Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate.
Impacted versions: < 2026-03-23
References
Code Behaviors & Features
Detect and mitigate GHSA-xmrv-pmrh-hhx2 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →