ex_aws_sns
ExAws.SNS service package
Activity
- Latest release
- 3mo ago
- Total releases
- 10
- Cadence
- ~11 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Nov 26, 2017
| Version | Released | |
|---|---|---|
2.3.5
patch
| ||
2.3.4
patch
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.3.3
patch
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.3.2
patch
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.3.1
patch
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2026-47074
GHSA-8jgf-23q5-x7xx
EEF-CVE-2026-47074
Jun 26, 2026
ex_aws_sns: Trusted-attacker `SigningCertURL` permits complete SNS signature bypass
High
Network
Low
None
None
Summary
DetailsIn Neither PoC
ConfigurationsThe application must expose an HTTP endpoint that calls ImpactComplete SNS signature authentication bypass. Affects Resources
Affected versions
2.0.1
2.1.0
2.2.0
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
Fixed in
2.3.5
References
Updated Jun 30, 2026 · Source: OSV.dev | ||
2.0.0
initial
|