CVE-2026-3337Disclosure(amazon / aws-lc-fips-sys)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch amazon aws-lc-fips-sys systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-208

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aws-lc-fips-sys
  • aws-lc-sys
  • aws_libcrypto

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-02); latest day: 2
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
aws-lc-fips-sysaws-lc-sysaws_libcrypto

Deep dive

Activity timeline8 mentions / 4d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-03: 2Mentions · 2026-03-06: 2Mentions · 2026-03-08: 2PoC Mentioned / Linked · 2026-03-08: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 203-0203-0303-0603-08
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-032
Disclosure1Patch1
2026-03-062
Disclosure1General1
2026-03-082
Disclosure2
Full discourse8 posts
  • Hunt.io@Huntio
    Disclosure

    🚨 Three AWS-LC Bugs Expose Signature and Encryption Risks https://securityonline.info/cracking-the-clouds-crypto-unauthenticated-bypass-flaws-found-in-amazons-aws-lc-library/ Three vulnerabilities have been uncovered in AWS-LC, Amazon’s cryptographic library used across AWS and many applications. Two flaws (CVE-2026-3336, CVE-2026-3338) allow unauthenticated attackers to bypass certificate and signature validation in PKCS7_verify(). A third (CVE-2026-3337) introduces a timing side-channel in AES-CCM decryption that could reveal authentication tag validity. The issues affect multiple AWS-LC versions and have been fixed in v1.69.0. Developers using the library or its Rust bindings should update ASAP. #CloudSecurity #CyberSecurity #AWS

    Post summary

    Three AWS‑LC CVEs are disclosed that allow signature bypasses and a timing side‑channel; patches are available in v1.69.0 with an update recommendation.

    12060930
    5.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    3 CVEs in AWS-LC general-purpose cryptographic library https://www.openwall.com/lists/oss-security/2026/03/03/7 CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification CVE-2026-3338: PKCS7_verify Signature Validation bypass

    Post summary

    Three new CVEs (CVE-2026-3336, 3337, 3338) affecting AWS‑LC’s PKCS7_verify and AES‑CCM functions were announced, with technical details but no PoC, exploit, or patch information.

    01021412
    4.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3337 Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. … https://www.cve.org/CVERecord?id=CVE-2026-3337 ----- Traducción: CVE-2026-3337 Dis… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3337, a timing‑based vulnerability in AWS‑LC’s AES‑CCM decryption that could allow unauthenticated users to infer authentication tag validity.

    0000189
    55 followersView on X
  • Sohan Kanna@Sohan_Intel
    Disclosure

    CVE-2026-3337 (CVSS 8.2): AES-CCM Timing Leak Decryption times vary via EVP CIPHER API. Attackers can precisely measure microsecond discrepancies to deduce authentication tag validity without the key! (Simulated leak below). https://t.co/HIKSQHFwy4

    Post summary

    The tweet discloses CVE-2026-3337 as an AES-CCM timing leak with a CVSS score of 8.2, includes a link to a simulated proof of concept, but does not mention active exploitation or a remedy.

    0000057
    1 followersView on X
  • Alex Pulver@alex_pulver
    General

    Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338) https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/

    Post summary

    The post simply flags three CVE identifiers related to AWS-LC without providing technical details, exploits, or patch information.

    0000066
    375 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3337 - Timing Side-Channel in AES-CCM Tag Verification in AWS-LC Intel Report: https://ift.tt/z7qh15j

    Post summary

    A new timing side‑channel vulnerability (CVE-2026-3337) affecting AES‑CCM tag verification in AWS‑LC has been reported, with an Intel report linked for further details.

    0000086
    342 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, profissionais de cibersegurança! Uma discrepância de tempo no AWS‑LC pode permitir ataques de cronometragem em AES‑CCM. 🔓 Atualize para a versão 1.69.0 para proteger suas aplicações! Detalhes aqui: https://www.tenable.com/cve/CVE-2026-3337 #Cybersecurity #AWS #CVE2026

    Post summary

    The post warns of a timing discrepancy in AWS‑LC that could enable timing attacks on AES‑CCM and advises updating to version 1.69.0 to mitigate the vulnerability.

    0000093
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3337 Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. … https://www.cve.org/CVERecord?id=CVE-2026-3337

    Post summary

    CVE‑2026‑3337 highlights a timing‑based vulnerability in AWS‑LC’s AES‑CCM decryption that could allow unauthenticated users to infer authentication tag validity.

    00000525
    56.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonaws-lc-fips-sys-rust-
Appamazonaws-lc-sys-rust-
Appamazonaws_libcrypto---
Appamazonaws_libcrypto---

Explore more