Moderate DoS Vulnerabilities in Amazon CloudWatch Agent Fixed

Moderate DoS Vulnerabilities in Amazon CloudWatch Agent Fixed

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

SUSE and openSUSE released updates for the Amazon CloudWatch Agent to address two vulnerabilities: CVE-2026-37236 and CVE-2026-41178. CVE-2026-37236 allows clients to bypass access control by overriding the HTTP method of a POST request, while CVE-2026-41178 permits denial-of-service (DoS) attacks via oversized inputs in baggage parsing. The vulnerabilities affect multiple SUSE Linux Enterprise and openSUSE versions, including Public Cloud Modules. The updates are rated as moderate in severity, and users are advised to apply patches using recommended installation methods. The CVEs were published on August 28, 2026, and June 4, 2026, respectively. Administrators should prioritize patching to mitigate potential risks.

Key Points: • Two vulnerabilities in Amazon CloudWatch Agent fixed: CVE-2026-37236 and CVE-2026-41178. • CVE-2026-37236 allows HTTP method bypass, while CVE-2026-41178 enables DoS via oversized inputs. • Affected systems include SUSE Linux Enterprise and openSUSE versions; patches are available.

Ask AI about this cluster

Timeline

2026-06-04
CVE-2026-41178 published
Vulnerability allows denial-of-service via oversized inputs in baggage parsing.
Linuxsecurity
2026-08-28
CVE-2026-37236 published
Vulnerability enables clients to bypass access control by overriding HTTP methods.
Linuxsecurity
2026-09-07
Patch released for Amazon CloudWatch Agent
SUSE and openSUSE released updates to address the identified vulnerabilities.
Linuxsecurity