CVE-2026-3338Disclosure(amazon / aws-lc-sys)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch amazon aws-lc-sys systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aws-lc-sys
  • aws_libcrypto

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-02); latest day: 2
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
aws-lc-sysaws_libcrypto

Deep dive

Activity timeline8 mentions / 5d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 2Mentions · 2026-03-08: 2Patch / Workaround · 2026-03-06: 2Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 203-0203-0303-0503-0603-08
Signal classification2 categories
Disclosure
787.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-022
Disclosure2
2026-03-031
Disclosure1
2026-03-051
Disclosure1
2026-03-062
Disclosure1Patch1
2026-03-082
Disclosure2
Full discourse8 posts
  • Hunt.io@Huntio
    Patch

    🚨 Three AWS-LC Bugs Expose Signature and Encryption Risks https://securityonline.info/cracking-the-clouds-crypto-unauthenticated-bypass-flaws-found-in-amazons-aws-lc-library/ Three vulnerabilities have been uncovered in AWS-LC, Amazon’s cryptographic library used across AWS and many applications. Two flaws (CVE-2026-3336, CVE-2026-3338) allow unauthenticated attackers to bypass certificate and signature validation in PKCS7_verify(). A third (CVE-2026-3337) introduces a timing side-channel in AES-CCM decryption that could reveal authentication tag validity. The issues affect multiple AWS-LC versions and have been fixed in v1.69.0. Developers using the library or its Rust bindings should update ASAP. #CloudSecurity #CyberSecurity #AWS

    Post summary

    The post discloses three AWS‑LC cryptographic bugs that bypass validation and reveal a timing side‑channel, but highlights that the vulnerabilities are patched in v1.69.0 and recommends immediate update.

    12060930
    5.1K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    3 CVEs in AWS-LC general-purpose cryptographic library https://www.openwall.com/lists/oss-security/2026/03/03/7 CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification CVE-2026-3338: PKCS7_verify Signature Validation bypass

    Post summary

    Three newly disclosed CVEs affecting AWS‑LC’s general‑purpose cryptographic library are listed with concise vulnerability names and brief technical descriptions, but no details on PoC, exploits, patches, or active exploitation.

    01021412
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3338 Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticat… https://www.cve.org/CVERecord?id=CVE-2026-3338

    Post summary

    The CVE-2026-3338 vulnerability involves improper signature validation in AWS-LC's PKCS7_verify(), allowing unauthenticated users to bypass signature checks when processing PKCS7 objects.

    00001368
    56.6K followersView on X
  • Sohan Kanna@Sohan_Intel
    Disclosure

    CVE-2026-3338 (CVSS 8.7): PKCS7 Signature Bypass Another logic flaw in PKCS7_verify(). Fails to validate signatures when handling objects with 'Authenticated Attributes'. Attackers manipulate this to force acceptance of invalid signatures, breaking integrity. ⬇️ https://t.co/rzktHN1LdE

    Post summary

    A new logic flaw in PKCS7_verify (CVE‑2026‑3338) allows attackers to bypass signature validation, accept invalid signatures, and compromise integrity, with a CVSS score of 8.7.

    0000045
    1 followersView on X
  • Alex Pulver@alex_pulver
    Disclosure

    Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338) https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/

    Post summary

    The statement announces issues (CVE-2026-3336/3337/3338) with AWS-LC and directs readers to an AWS security bulletin, indicating a vulnerability disclosure that likely includes patch information.

    0000066
    375 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    AWS PKCS7_verify vulnerabilities CVE-2026-3336 and CVE-2026-3338 allow certificate chain and signature validation bypass, potentially compromising cryptographic integrity in AWS environments. https://threatcluster.io/cluster/multiple-pkcs7_verify-vulnerabilities-discovered-in-aws-9737720e

    Post summary

    AWS has disclosed two PKCS7_verify vulnerabilities (CVE-2026-3336 and CVE-2026-3338) that bypass certificate chain and signature validation, potentially compromising cryptographic integrity in AWS environments.

    0000043
    91 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3338 - PKCS7_verify Signature Validation Bypass in AWS-LC Intel Report: https://ift.tt/SyYzMZk

    Post summary

    Alert announces CVE-2026-3338, a PKCS7_verify signature validation bypass in AWS-LC, with an Intel report linked for further details.

    0000070
    342 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3338 Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticat… https://www.cve.org/CVERecord?id=CVE-2026-3338 ----- Traducción: CVE-2026-3338 Val… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3338, detailing an improper signature validation flaw in AWS‑LC that permits unauthenticated bypass of PKCS7 signature verification, but offers no PoC, exploit, or patch information.

    0000066
    55 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonaws-lc-sys-rust-
Appamazonaws_libcrypto---

Explore more