CVE-2026-3337
CVSS 5.9 MEDIUM: observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine… EPSS 1% (61st percentile), up from 0.04%.
Vulnerabilities & Exploits
AWS published an advisory for three vulnerabilities in the AWS‑LC cryptographic library. Unauthenticated actors can bypass PKCS7 signature and certificate‑chain validation on certain PKCS7 objects. A separate timing side‑channel can disclose AES‑CCM authentication tag validity on affected builds.
1 source · Mar 3
CVSS 5.9 MEDIUM: observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine… EPSS 1% (61st percentile), up from 0.04%.
CVSS 7.5 HIGH: improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature… EPSS 0.8% (51st percentile).
CVSS 7.5 HIGH: improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate… EPSS 0.8% (51st percentile).
AWS Security Bulletins
Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)
We identified three distinct issues:</p> <p>- CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC<br/> Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.<br/> - CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC<br/> Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.<br/> - CVE-2026-3338: PKCS7_verify Signature Validation bypass in AWS-LC<br/> Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.</p> <p><b>Impacted versions:</b></p> <p>- PKCS7_verify Certificate Chain Validation Bypass in AWS-LC >= v1.41.0, < v1.69.0<br/> - PKCS7_verify Certificate Chain Validation Bypass in aws-lc-sys >= v0.24.0, < v0.38.0<br/> - Timing Side-Channel in AES-CCM Tag Verification in AWS-LC >= v1.21.0, < v1.69.0<br/> - Timing Side-Channel in AES-CCM Tag Verification in AWS-LC >= AWS-LC-FIPS-3.0.0, < AWS-LC-FIPS-3.2.0<br/> - Timing Side-Channel in AES-CCM Tag Verification in aws-lc-sys >= v0.14.0, < v0.38.0<br/> - Timing Side-Channel in AES-CCM Tag Verification in aws-lc-sys-fips >= v0.13.0, < v0.13.12<br/> - PKCS7_verify Signature Validation bypass in AWS-LC >= v1.41.0, < v1.69.0<br/> - PKCS7_verify Signature Validation bypass in aws-lc-sys >= v0.24.0, < v0.38.0</p> <p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>
originalAWS Security Bulletins
Security Findings in SageMaker Python SDK
<p><b>Bulletin ID:</b> 2026-004-AWS<br/> <b>Scope:</b> AWS<br/> <b>Content Type:</b> Important (requires attention)<br/> <b>Publication Date:</b> 2026/02/02 14:30 PM PST</p> <p><b>Description:</b></p> <p>CVE-2026-1777 - Exposed HMAC in SageMaker Python SDK<br/> SageMaker Python SDK’s remote functions feature uses a per‑job HMAC key to protect the integrity of serialized functions, arguments, and results stored in S3. We identified an issue where the HMAC secret key is stored in environment variables and disclosed via the DescribeTrainingJob API. This allows third parties with DescribeTrainingJob permissions to extract the key, forge cloud-pickled payloads with valid HMACs, and overwrite S3 objects.</p> <p>CVE-2026-1778 - Insecure TLS Configuration in SageMaker Python SDK<br/> SageMaker Python SDK is an open source library for training and deploying machine learning models on Amazon SageMaker. We identified an issue where SSL certificate verification was globally disabled in the Triton Python backend. This configuration was introduced to work around SSL errors during model downloads from public sources (e.g., TorchVision) and it affected all HTTPS connections when the Triton Python model was imported.</p> <p><b>Impacted versions:</b></p> <p>- HMAC Configuration in SageMaker Python SDK v3 < v3.2.0<br/> - HMAC Configuration in SageMaker Python SDK v2 < v2.256.0<br/> - Insecure TLS Configuration in SageMaker Python SDK v3 < v3.1.1<br/> - Insecure TLS Configuration in SageMaker Python SDK v2 < v2.256.0</p> <p><b>Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.</b></p>
originalPart of the PlainSec briefing for 2026-03-03
Every edition of this story: AWS‑LC Crypto Flaws Enable PKCS7 Bypass and Timing Leak