CVE-2026-3338: Amazon Aws-Lc-Sys
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Affected products
- Amazon Aws-Lc-Sys: from 0.24.0, before 0.38.0 (fixed in 0.38.0)
- Amazon Aws Libcrypto: from 1.41.0, before 1.69.0 (fixed in 1.69.0)
Published 2026-03-02. Last modified 2026-07-15.