AWS Amazon Q Developer patch for CVE-2026-12957 and CVE-2026-12958
Security Patch Release
Summary
Hide ▲
Show ▼
AWS released fixes for Amazon Q Developer after a high-severity flaw in the VS Code extension could expose developers’ cloud credentials. The patch set covers CVE-2026-12957 and a related CVE-2026-12958 symbolic-link issue. Fixes are available across affected Amazon Q Developer plugins and the language server.
Related Happenings
Amazon security patch release for CVE-2026-50549
Security Patch Release
H score29
First: 09.07.2026 14:00
Last: 09.07.2026 14:00
Sources 1
About this happening:
Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...
Amazon security patch release for CVE-2026-50549
Security Patch ReleaseAbout this happening: Amazon, Google and Cursor shipped fixes for GhostApproval, a flaw in AI coding assistants that let deceptive repository paths bypass approval prompts. The patch response c...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Squid web proxy patch for CVE-2026-47729
Security Patch Release
H score20
First: 22.06.2026 17:29
Last: 22.06.2026 17:29
Sources 1
About this happening:
Squid maintainers merged a null-terminator check for CVE-2026-47729 into the development branch and v7, closing the FTP-parser over-read that could expose shar...
Squid web proxy patch for CVE-2026-47729
Security Patch ReleaseAbout this happening: Squid maintainers merged a null-terminator check for CVE-2026-47729 into the development branch and v7, closing the FTP-parser over-read that could expose shar...
Ivanti security patch release for CVE-2026-8043
Security Patch Release
H score25
First: 18.05.2026 13:54
Last: 18.05.2026 13:54
Sources 1
About this happening:
Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Ivanti security patch release for CVE-2026-8043
Security Patch ReleaseAbout this happening: Ivanti, Fortinet, SAP, Broadcom, and n8n released security fixes on 2026-05-18 for flaws that could enable authentication bypass, remote code execution, SQL...
Google security patch release for CVE-2026-5858
Security Patch Release
H score16
First: 10.04.2026 13:44
Last: 10.04.2026 13:44
Sources 1
About this happening:
Google released the first stable Chrome 147 build, closing 60 vulnerabilities and raising the browser’s baseline security ahead of broader deployment. The patch bundle...
Google security patch release for CVE-2026-5858
Security Patch ReleaseAbout this happening: Google released the first stable Chrome 147 build, closing 60 vulnerabilities and raising the browser’s baseline security ahead of broader deployment. The patch bundle...
Timeline
-
26.06.2026 18:23 1 articles · 19d ago
AWS receives notice of Amazon Q Developer flaw
Initial DisclosureAWS was notified about a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could let a malicious repository auto-run commands and expose developers’ cloud credentials and API keys.
Show sources
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories — www.securityweek.com — 26.06.2026 18:23
-
26.06.2026 18:23 2 articles · 19d ago
AWS patches Amazon Q Developer CVE-2026-12957 and CVE-2026-12958
Mitigation Patch UpdateAWS releases fixes for CVE-2026-12957 and the related symbolic-link issue CVE-2026-12958 across affected Amazon Q Developer plugins and the language server, including language server version 1.65.0.
Show sources
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories — www.securityweek.com — 26.06.2026 18:23
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories — www.securityweek.com — 26.06.2026 18:23
-
26.06.2026 03:00 1 articles · 20d ago
Wiz publishes technical details and PoC code for Amazon Q Developer flaw
Technical Analysis UpdateWiz publishes technical details and PoC code showing how a malicious repository could trigger auto-execution in Amazon Q Developer and expose developers’ cloud credentials and API keys.
Show sources
- Amazon Q Flaw Enabled Cloud Credential Theft via Malicious Repositories — www.securityweek.com — 26.06.2026 18:23