CVE-2026-90513 PUBLISHED

simalexan api-lambda-send-email-ses API Gateway Endpoint template.yml SES.sendEmail missing authentication

Assigner: VulDB
Reserved: 12.09.2026 Published: 13.09.2026 Updated: 13.09.2026

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 6.9

Product Status

Vendor simalexan
Product api-lambda-send-email-ses
Versions
  • Version bda6869aa81371d1e872242e74fe7d953edb818d is affected

Credits

  • changli (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Missing Authentication CWE
  • Improper Authentication CWE