Vulnerabilities & Exploits

AWS‑LC Crypto Flaws Enable PKCS7 Bypass and Timing Leak

AWS published an advisory for three vulnerabilities in the AWS‑LC cryptographic library. Unauthenticated actors can bypass PKCS7 signature and certificate‑chain validation on certain PKCS7 objects. A separate timing side‑channel can disclose AES‑CCM authentication tag validity on affected builds.

1 source · Mar 3

CVE-2026-3337

NVD KEV

CVSS 5.9 MEDIUM: observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine… EPSS 1% (61st percentile), up from 0.04%.

CVE-2026-3338

NVD KEV

CVSS 7.5 HIGH: improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature… EPSS 0.8% (51st percentile).

CVE-2026-3336

NVD KEV

CVSS 7.5 HIGH: improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate… EPSS 0.8% (51st percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-03

Every edition of this story: AWS‑LC Crypto Flaws Enable PKCS7 Bypass and Timing Leak

More from today