bartek@aws: ~/news
$ whoami

Bartek Chojnacki

$ AWS Architect · DevOps · Cloud
Thursday, August 13, 2026

OpenSearch SQL Plugin Vulnerability Lets Users Bypass Security Rules

OpenSearch SQL Plugin versions 2.13–3.6 have a nasty security gap: the Flint extension doesn't properly validate async queries, letting users slip past the SQL grammar deny list through direct queries. If you're running affected versions, you need to update to 3.7 or 2.19.6 ASAP. AWS managed OpenSearch users get automatic fixes via service updates.

source: [aws/security-bulletin]

OpenSearch Security Analytics Plugin: SSRF Vulnerability Requires Update

OpenSearch Security Analytics Plugin has a critical input validation flaw (CVE-2026-18952) that lets authenticated users perform server-side request forgery and read local files. If you're running plugin version 2.15.0 or later, you need to upgrade to 3.5.0 or newer. AWS managed domains are mostly safe since the vulnerable feature isn't enabled by default, but self-managed instances require immediate patching.

source: [aws/security-bulletin]

also that day:

Wednesday, August 12, 2026

AWS SDK for C++ Base64 Decoder Vulnerabilities Require Immediate Update

AWS SDK for C++ versions up to 1.11.861 contain two memory-safety bugs (CVE-2026-19642 and CVE-2026-19643) in the Base64 decoder that could crash your app or corrupt memory. CVE-2026-19642 causes out-of-bounds writes, while CVE-2026-19643 triggers out-of-bounds reads on certain platforms. Yes, you need to act—update your SDK immediately if you're using an affected version. Remote code execution hasn't been demonstrated, but the impact is real for any process decoding untrusted Base64 data.

source: [aws/security-bulletin]

OpenSearch Alerting Plugin: Authorization Bypass Requires Immediate Patching

OpenSearch Alerting Plugin has a nasty authorization flaw (CVE-2026-19311) that lets authenticated users with alerting_full_access role read, modify, or delete arbitrary index data through crafted monitor requests. Affected versions: 2.4.0–2.19.5 and 3.0.0–3.7.0 (self-managed), plus AWS OpenSearch Service domains on engines 2.4–3.5. Action required: upgrade to 2.19.6, 3.8.0, or service software R20260428-P3 immediately.

source: [aws/security-bulletin]

also that day:

Tuesday, August 11, 2026

AWS Landing Zone Accelerator Gets C5:2020 Compliance Stamp

AWS just dropped an independent assessment report for Landing Zone Accelerator on AWS Artifact, proving it meets Germany's strict C5:2020 cloud security standards. If you're deploying infrastructure in Europe and need to tick compliance boxes without reinventing the wheel, this assessment gives you a solid foundation to build on.

source: [aws/security-blog]

also that day: