Silicon Angle reports that Amazon Web Services (AWS) has addressed a security flaw affecting seven of its software development kits (SDKs) following an investigation by product security startup Pi Inc. The vulnerability was found to exist in approximately 2,500 instances.The flaw allowed for the redirection of API calls by manipulating the region field within the SDK's hostname template. Researchers at Pi Inc. discovered that by inputting a specially crafted string, such as "@attacker.com#", into the region field, the SDK would construct a URL pointing to an attacker-controlled domain. While ordinary API calls could be redirected, a critical vulnerability emerged with the AssumeRoleWithWebIdentity call, used by services like Elastic Kubernetes Service and Cognito. This specific call transmits a bearer token in plaintext within its request body. In testing, this token was captured and replayed to AWS Security Token Service, successfully returning live credentials for the customer's account, according to Pi Inc.AWS has since patched the issue by implementing region validation within each generated SDK, ensuring that the region is treated as a valid host label. Pi Inc. reported the vulnerability on Oct. 14, 2025, with advisories released in January. AWS has characterized the fix as a defense-in-depth enhancement, emphasizing developer responsibility for input validation.Source: Silicon Angle
Cloud Security
AWS patches flaw in 7 SDKs
(Adobe Stock)
An In-Depth Guide to Cloud Security
Get essential knowledge and practical strategies to fortify your cloud security.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
