CVE-2024-23680: Amazon Aws Encryption SDK

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Affected products

  • Amazon Aws Encryption SDK: before 1.9.0 (fixed in 1.9.0); from 2.0.0, before 2.2.0 (fixed in 2.2.0)

Published 2024-01-19. Last modified 2026-07-14.