CVE-2026-3336Disclosure(amazon / aws-lc-sys)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch amazon aws-lc-sys systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aws-lc-sys
  • aws_libcrypto

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-02); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
aws-lc-sysaws_libcrypto

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-08: 2Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 2Technical Details · 2026-03-12: 103-0203-0503-0603-0803-12
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-051
Disclosure1
2026-03-062
General1Patch1
2026-03-082
Disclosure2
2026-03-121
Disclosure1
Full discourse8 posts
  • Hunt.io@Huntio
    Patch

    🚨 Three AWS-LC Bugs Expose Signature and Encryption Risks https://securityonline.info/cracking-the-clouds-crypto-unauthenticated-bypass-flaws-found-in-amazons-aws-lc-library/ Three vulnerabilities have been uncovered in AWS-LC, Amazon’s cryptographic library used across AWS and many applications. Two flaws (CVE-2026-3336, CVE-2026-3338) allow unauthenticated attackers to bypass certificate and signature validation in PKCS7_verify(). A third (CVE-2026-3337) introduces a timing side-channel in AES-CCM decryption that could reveal authentication tag validity. The issues affect multiple AWS-LC versions and have been fixed in v1.69.0. Developers using the library or its Rust bindings should update ASAP. #CloudSecurity #CyberSecurity #AWS

    Post summary

    The post announces three CVEs in AWS‑LC that allow authentication bypass or side‑channel leaks and emphasizes that the fix is in version 1.69.0, urging immediate update.

    12060930
    5.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    3 CVEs in AWS-LC general-purpose cryptographic library https://www.openwall.com/lists/oss-security/2026/03/03/7 CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification CVE-2026-3338: PKCS7_verify Signature Validation bypass

    Post summary

    Three new CVEs in AWS‑LC are disclosed, covering PKCS7_verify certificate chain and signature validation bypasses and a timing side‑channel in AES-CCM tag verification.

    01021412
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Amazon AWS-LC の脆弱性 CVE-2026-3336/3337/3338 が FIX:証明書検証の回避の恐れ https://iototsecnews.jp/2026/03/06/aws-lc-flaw-exposes-amazon-users-to-attacks-by-bypassing-certificate-chain-validation/ Amazonのオープンソース暗号ライブラリ AWS-LC において、デジタル署名の検証手順と、復号処理における時間の管理に不備が生じています。AWS-LC は、数多くのクラウド通信やアプリで使われている ため、その影響が懸念されています。今回、新たに発見された脆弱性は、署名が本物であることを確認するプロセス (PKCS7_verify 関数) のショートカットを許してしまうものや、暗号の正誤を判定する際の時間の差から正解の推測を許してしまうものです。これらの欠陥を突く攻撃者は、偽の証明書を用いることで、通信内容の解析などを引き起こす可能性があります。ご利用のチームは、ご注意ください。 #Amazon #AWS #AWSLC #CVE20263336 #CVE20263337 #CVE20263338 #Vulnerability

    Post summary

    The article announces AWS‑LC vulnerabilities (CVE‑2026‑3336‑3338) that allow certificate validation bypass and timing attacks, providing technical details but no patches, PoCs, or evidence of active exploitation.

    02010167
    484 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3336 Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with m… https://www.cve.org/CVERecord?id=CVE-2026-3336

    Post summary

    The text provides a brief disclosure of CVE-2026-3336, detailing an improper certificate validation flaw in AWS-LC's PKCS7_verify() that allows unauthenticated bypass of certificate chain verification.

    00002808
    56.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3336 Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with m… https://www.cve.org/CVERecord?id=CVE-2026-3336 ----- Traducción: CVE-2026-3336 Val… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3336, describing a certificate validation flaw in AWS‑LC’s PKCS7_verify() that permits unauthenticated bypass of certificate chain verification, but it provides no PoC, exploit, or patch details.

    0000183
    55 followersView on X
  • Sohan Kanna@Sohan_Intel
    Disclosure

    CVE-2026-3336 (CVSS 8.7): PKCS7_verify Cert Bypass Flaw in PKCS7_verify(). When processing PKCS7 objects with multiple signers, AWS-LC only checks the final signer. Attackers can build payloads ignoring invalid upstream certs, bypassing the trust chain. https://t.co/yg78T0dzWg

    Post summary

    The tweet announces CVE-2026-3336, a serious PKCS7_verify certificate bypass flaw in AWS-LC, detailing how attackers can ignore invalid upstream certs in multi-signer PKCS7 objects, potentially compromising trust chains.

    0000049
    1 followersView on X
  • Alex Pulver@alex_pulver
    General

    Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338) https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/

    Post summary

    The statement announces three CVEs affecting AWS‑LC and provides a link to Amazon’s security bulletin, but offers no details on exploitation, patches, or technical specifics.

    0000066
    375 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    AWS PKCS7_verify vulnerabilities CVE-2026-3336 and CVE-2026-3338 allow certificate chain and signature validation bypass, potentially compromising cryptographic integrity in AWS environments. https://threatcluster.io/cluster/multiple-pkcs7_verify-vulnerabilities-discovered-in-aws-9737720e

    Post summary

    Two new AWS PKCS7_verify CVEs (CVE-2026-3336 & CVE-2026-3338) are disclosed, allowing bypass of certificate chain and signature validation, potentially compromising cryptographic integrity in AWS environments.

    0000043
    91 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonaws-lc-sys-rust-
Appamazonaws_libcrypto---

Explore more