Hunt.io[verified]@HuntioPatch
The post announces three CVEs in AWS‑LC that allow authentication bypass or side‑channel leaks and emphasizes that the fix is in version 1.69.0, urging immediate update.
ThreatCluster[verified]@threatclusterDisclosure
Two new AWS PKCS7_verify CVEs (CVE-2026-3336 & CVE-2026-3338) are disclosed, allowing bypass of certificate chain and signature validation, potentially compromising cryptographic integrity in AWS environments.
Open Source Security mailing list@oss_securityDisclosure
Three new CVEs in AWS‑LC are disclosed, covering PKCS7_verify certificate chain and signature validation bypasses and a timing side‑channel in AES-CCM tag verification.
iototsecnews@iototsecnewsDisclosure
The article announces AWS‑LC vulnerabilities (CVE‑2026‑3336‑3338) that allow certificate validation bypass and timing attacks, providing technical details but no patches, PoCs, or evidence of active exploitation.
CVE@CVEnewDisclosure
The text provides a brief disclosure of CVE-2026-3336, detailing an improper certificate validation flaw in AWS-LC's PKCS7_verify() that allows unauthenticated bypass of certificate chain verification.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑3336, describing a certificate validation flaw in AWS‑LC’s PKCS7_verify() that permits unauthenticated bypass of certificate chain verification, but it provides no PoC, exploit, or patch details.
Sohan Kanna@Sohan_IntelDisclosure
The tweet announces CVE-2026-3336, a serious PKCS7_verify certificate bypass flaw in AWS-LC, detailing how attackers can ignore invalid upstream certs in multi-signer PKCS7 objects, potentially compromising trust chains.
Alex Pulver@alex_pulverGeneral
The statement announces three CVEs affecting AWS‑LC and provides a link to Amazon’s security bulletin, but offers no details on exploitation, patches, or technical specifics.