CVE-2026-35559 PUBLISHED

Out-of-bounds write in query processing components in Amazon Athena ODBC driver

Assigner: AMZN
Reserved: 03.04.2026 Published: 03.04.2026 Updated: 03.04.2026

Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations.

To remediate this issue, users should upgrade to version 2.1.0.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Amazon
Product Amazon Athena ODBC driver
Versions Default: unaffected
  • Version 2.1.0.0 is unaffected

References

Problem Types

  • CWE-787 Out-of-bounds write CWE

Impacts

  • CAPEC-153 Input Data Manipulation