logo

Cracking the Cloud’s Crypto: Unauthenticated Bypass Flaws Found in Amazon’s AWS-LC Library

ID: 910c11fe-022d-5a46-b307-1bdf4c86e9fa

STIX ID: report--910c11fe-022d-5a46-b307-1bdf4c86e9fa

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed three vulnerabilities in AWS-LC—two high-severity PKCS7 certificate/signature validation bypasses (CVE-2026-3336 and CVE-2026-3338, CVSS 7.5) and a timing side‑channel in AES‑CCM tag verification (CVE-2026-3337, CVSS 5.9). The issues affect AWS-LC and aws-lc-sys releases prior to v1.69.0/v0.38.0 (with FIPS builds addressed in AWS-LC-FIPS v3.2.0/aws-lc-sys-fips v0.13.12), have no known workarounds, and users and developers are advised to upgrade immediately to the fixed versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.