PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
High7.5CVE-2026-3336 · Published Mar 2, 2026 · updated Mar 3, 2026
### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. ### Acknowledgement We would like to thank Joshua Rogers (https://joshua.hu/) of AISLE Research Team (https://aisle.com) for collaborating on this issue through the coordinated vulnerability disclosure process.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AWS-LC Product | >= v1.41, < v1.69.0 | v1.69.0 |
Details and references
### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. ### Acknowledgement We would like to thank Joshua Rogers (https://joshua.hu/) of AISLE Research Team (https://aisle.com) for collaborating on this issue through the coordinated vulnerability disclosure process.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 19 | CRL Distribution Point Scope Check Logic Error in AWS-LC | High7.4 | 1.71.0+1 more |
| Mar 5 | Defense-in-depth: Replaced eval() with safe parser in JumpStart search functionality | High8.4 | 3.4.0 |
| Mar 2 | PKCS7_verify Signature Validation Bypass in AWS-LC | High7.5 | v1.69.0 |
| Mar 2 | Timing Side-Channel in AES-CCM Tag Verification in AWS-LC | Medium5.9 | v1.69.0+1 more |
| Mar 2 | Memory overallocation in aws-kms-tls-auth | Low3.7 | 0.0.3 |
| Feb 25 | cli_history database does not restrict file permissions on Unix systems | Medium5.9 | 1.44.37+1 more |