aws-sdk-ec2instanceconnect
AWS SDK for AWS EC2 Instance Connect
Activity
- Latest release
- 1w ago
- Total releases
- 158
- Cadence
- ~8 days
- Last 12 months
- 26
Reach
- Downloads
- 195.6k
Details
- License
- Apache-2.0
- First release
- May 07, 2021
| Version | Released | |
|---|---|---|
1.110.0
minor
|
1.110.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.109.0
minor
|
1.109.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.108.0
minor
|
1.108.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.107.0
minor
|
1.107.0
minor
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.106.0
unknown
|
1.106.0
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.105.0
unknown
|
1.105.0
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.104.0
unknown
|
1.104.0
unknown
Dependencies (21)
+ 13 more
Changelog
Compare changes
|
|
1.103.0
unknown
|
1.103.0
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
1.102.0
unknown
|
1.102.0
unknown
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
1.101.0
unknown
|
1.101.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.100.0
unknown
|
1.100.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.99.0
unknown
|
1.99.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.98.0
unknown
|
1.98.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.97.0
unknown
|
1.97.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.96.0
unknown
|
1.96.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.95.0
unknown
|
1.95.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.94.0
unknown
|
1.94.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.93.0
unknown
|
1.93.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.92.0
unknown
|
1.92.0
unknown
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
1.91.0
unknown
|
1.91.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.90.0
unknown
|
1.90.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.89.0
unknown
|
1.89.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.88.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.88.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.87.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.87.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.86.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.86.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.85.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.85.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.84.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.84.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.83.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.83.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.82.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.82.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.81.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.81.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.80.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.80.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.79.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.79.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.78.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.78.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.77.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.77.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.76.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.76.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.75.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.75.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.74.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.74.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.73.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.73.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.72.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.72.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.71.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.71.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.70.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.70.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.69.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.69.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.68.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.68.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.67.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.67.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.66.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.66.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.65.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.65.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.64.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.64.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.63.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.63.0
unknown
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
1.62.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.62.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
1.61.0
unknown
1 CVE
GHSA-g59m-gf8j-gjf5
Jan 08, 2026
AWS SDK for Rust v1 adopted defense in depth enhancement for region parameter value
3.7
/ 10
Low
Network
High
None
None
Unchanged
Low
None
None
SummaryThis notification is related to the use of specific values for the region input field when calling AWS services. An actor with access to the environment in which the SDK is used could set the region input field to an invalid value. A defense-in-depth enhancement has been implemented in the AWS SDK for Rust. This enhancement validates that a region used to construct an endpoint URL is a valid host label. The change was released on November 6, 2025. This advisory is informational to help customers understand their responsibilities regarding configuration security. ImpactCustomer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Impacted versions: All versions prior to November 6, 2025 release PatchesOn November 6, 2025, an enhancement [1] was made to the AWS SDK for Rust release, which validates the formatting of a region, providing additional safeguards. WorkaroundsNo workarounds are needed, but as always developers should ensure that their application is following security best practices:
ReferencesContact AWS Security via the vulnerability reporting page or email aws-security@amazon.com. AcknowledgementAWS Security thanks Guy Arazi for bringing these customer security considerations to our attention through the coordinated disclosure process. [1] https://github.com/smithy-lang/smithy-rs/pull/4383 [2] https://docs.aws.amazon.com/sdk-for-rust/latest/dg/security.html Fixed in
1.89.0
References Updated Sep 10, 2026 · Source: OSV.dev |
1.61.0
unknown
Dependencies (17)
+ 9 more
Changelog
Compare changes
|