
🚨 Three AWS-LC Bugs Expose Signature and Encryption Risks https://securityonline.info/cracking-the-clouds-crypto-unauthenticated-bypass-flaws-found-in-amazons-aws-lc-library/ Three vulnerabilities have been uncovered in AWS-LC, Amazon’s cryptographic library used across AWS and many applications. Two flaws (CVE-2026-3336, CVE-2026-3338) allow unauthenticated attackers to bypass certificate and signature validation in PKCS7_verify(). A third (CVE-2026-3337) introduces a timing side-channel in AES-CCM decryption that could reveal authentication tag validity. The issues affect multiple AWS-LC versions and have been fixed in v1.69.0. Developers using the library or its Rust bindings should update ASAP. #CloudSecurity #CyberSecurity #AWS
Post summary
The post discloses three AWS‑LC cryptographic bugs that bypass validation and reveal a timing side‑channel, but highlights that the vulnerabilities are patched in v1.69.0 and recommends immediate update.







