About “AWS Lambda”

A curated feed of “AWS Lambda”-related CVEs appears below. We currently track 8 CVEs for this tag (all time). In the last 365 days, 2 were published. Average CVSS is 6.9 (all time; 7.8 over 365d), and 62% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-290 - Authentication Bypass by Spoofing, CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection').

In our taxonomy this topic maps to a LOW impact class. Cloud and managed service CVEs involve shared responsibility. Check provider bulletins to confirm tenant actions, limit exposure, and rotate keys if advised. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

Support & lifecycle: aws-lambda

This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.

CycleReleaseLatestPremier SupportEOLLTS
ruby4.0-
dotnet10-
nodejs24.x-
python3.14-
java25-
ruby3.4-
dotnet9--
nodejs22.x-
python3.13-
ruby3.3-
dotnet8-
python3.12-
java21-
nodejs20.x-
provided.al2023-
python3.11-
ruby3.2-
java17-
python3.10-
nodejs18.x-
dotnet7-- Expired
nodejs16.x-
dotnet6-
python3.9-
nodejs14.x-
dotnet5.0-- Expired
java8.al2-
provided.al2-
dotnetcore3.1- Expired
ruby2.7-
nodejs12.x- Expired
python3.8-
java11-
nodejs10.x- Expired
ruby2.5- Expired
provided-
python3.7-
dotnetcore2.1- Expired
nodejs8.10- Expired
dotnetcore2.0- Expired
go1.x-
nodejs4.3-edge- Expired
python3.6- Expired
nodejs6.10- Expired
dotnetcore1.0- Expired
nodejs4.3- Expired
python2.7- Expired
java8-
nodejs- Expired

Maintained Soon (≤ 180 days) Expired

Subscribe lifecycle: RSS  ·  RSS (expired)  ·  ICS

Subscribe CVEs: RSS for “AWS Lambda”  ·  RSS (High+Critical only)

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2026-02-25
High

CVE-2026-27700

Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, when using the AWS Lambda adapter (`hono/aws-lambda`) behind an Application Load B…

2025-12-30
High

CVE-2025-69256

The Serverless Framework is a framework for using AWS Lambda and other managed cloud services to build applications. Starting in version 4.29.0 and prior to version 4.29.3, a command injection vulner…

2024-06-11
High

CVE-2024-37293

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, c…

2024-02-01
Low

CVE-2024-24754

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object.…

Medium

CVE-2024-24753

Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it does not handle multiple values headers. If PHP generates a response with two hea…

Medium

CVE-2024-24752

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object.…

2020-01-08
Critical

CVE-2019-10777

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject…

2018-03-04
High

CVE-2018-7560

index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a crafted multipart/form-data boundary string.

CVE Daily Lookup — auto-links CVE IDs on any page you visit. GitHub, Jira, Confluence & more. Free.