Third-Party Package Updates in Splunk Add-on for Amazon Web Services - September 2026
Advisory ID: SVD-2026-1005
CVE ID:
Published: 2026-10-07
Last Update: 2026-10-07
Description
Splunk remedied common vulnerabilities and exposures (CVEs) in third-party packages in Splunk Add-on for Amazon Web Services version 8.2.2 and higher.
| Package | Remediation | CVE | Severity |
|---|---|---|---|
| github.com/golang/go1 | Upgraded the Go compiler to version 1.26.4 | Multiple | Critical |
| golang.org/x/net2 | Upgraded golang.org/x/net to version 0.56.0 | Multiple | Critical |
| google.golang.org/grpc3 | Upgraded google.golang.org/grpc to version 1.79.3 | CVE-2026-33186 | Critical |
| github.com/apache/thrift4 | Upgraded github.com/apache/thrift to version 0.23.0 | CVE-2026-41602 | High |
| cryptography5 | Upgraded cryptography to version 50.0.0 | Multiple | High |
1 Upgraded the Go compiler to version 1.26.4 to remedy CVE-2025-61726, CVE-2025-61728, CVE-2025-61730, CVE-2025-68121, CVE-2026-25679, CVE-2026-27139, CVE-2026-27142, CVE-2026-27145, CVE-2026-32280, CVE-2026-32281, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289, CVE-2026-33811, CVE-2026-39820, CVE-2026-39823, CVE-2026-39825, CVE-2026-39826, CVE-2026-39836, CVE-2026-42499, CVE-2026-42504, and CVE-2026-42507 at $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_linux_amd64 and $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_windows_amd64.exe.
2 Upgraded golang.org/x/net to version 0.56.0 to remedy CVE-2025-22870, CVE-2025-22872, CVE-2025-47911, CVE-2025-58190, CVE-2026-33814, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-42506, and CVE-2026-46600 at $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_linux_amd64 and $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_windows_amd64.exe.
3 Upgraded google.golang.org/grpc to version 1.79.3 to remedy CVE-2026-33186 at $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_linux_amd64 and $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_windows_amd64.exe.
4 Upgraded github.com/apache/thrift to version 0.23.0 to remedy CVE-2026-41602 at $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_linux_amd64 and $SPLUNK_HOME/etc/apps/Splunk_TA_aws/bin/aws_parquet/parquet_decoder_windows_amd64.exe.
5 Upgraded cryptography to version 50.0.0 to remedy CVE-2026-26007, CVE-2026-34073, CVE-2026-34180, CVE-2026-39892, CVE-2026-69247, CVE-2026-69248, and CVE-2026-69249 in Splunk Add-on for Amazon Web Services version 8.2.2.
Solution
Upgrade Splunk Add-on for Amazon Web Services to version 8.2.2 or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Add-on for Amazon Web Services | 8.2 | Below 8.2.2 | 8.2.2 |
Severity
Unless otherwise stated, Splunk adopts the vendor’s severity rating first, if available, or the National Vulnerability Database (NVD)’s rating, otherwise.