// AWSMEDIUM
AWS patched a widespread input validation flaw across seven SDKs (Python, Ruby, Go, Java, Node.js, PHP, .NET) that allowed attackers to hijack region parameters in hostnames and redirect API calls to attacker-controlled servers. The flaw particularly affects AssumeRoleWithWebIdentity calls, leaking plaintext bearer tokens and AWS credentials from EKS workloads, Cognito applications, and OIDC integrations. Discovered by Pi Inc., the vulnerability was reported October 2025 and patched by January 2026; only the .NET SDK received a CVE (CVE-2026-22611, rated 3.7/10).
// Get alerts for AWS