CVE-2026-3338
Received
Received - Intake
Improper Signature Validation in AWS-LC PKCS7 Enables Bypass
Publication date: 2026-03-02
Last updated on: 2026-03-11
Assigner: AMZN
Description
Description
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amazon | aws_libcrypto | From 1.41.0 (inc) to 1.69.0 (exc) |
| amazon | aws-lc-sys | From 0.24.0 (inc) to 0.38.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |