← voltar
CVE-2026-22611

AWS SDK for .NET V4 adopted defense in depth enhancement for region parameter value

CVSS 3.7 LOWEPSS 0.2%CWE-20
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.7EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 jan 2026Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. This issue has been patched in version 4.0.3.3.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
aws · aws-sdk-net

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →