CVE-2026-3338: Amazon Aws-Lc-Sys

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

Affected products

  • Amazon Aws-Lc-Sys: from 0.24.0, before 0.38.0 (fixed in 0.38.0)
  • Amazon Aws Libcrypto: from 1.41.0, before 1.69.0 (fixed in 1.69.0)

Published 2026-03-02. Last modified 2026-07-15.