bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-3338

show all
Thursday, August 20, 2026

Three Critical Vulnerabilities Found in AWS-LC Cryptographic Library

AWS-LC, the open-source crypto library, has three nasty security issues that need your attention. CVE-2026-3336 and CVE-2026-3338 let attackers bypass certificate and signature validation in PKCS7_verify(), while CVE-2026-3337 introduces a timing side-channel in AES-CCM tag verification. If you're running AWS-LC versions 1.41.0–1.69.0 or aws-lc-sys 0.24.0–0.38.0, update immediately—these flaws affect multiple variants including FIPS versions.

source: [aws/security-bulletin]