Skip to content
AWSGHSA-cfwj-9wp5-wqvp

PKCS7_verify Certificate Chain Validation Bypass in AWS-LC

High7.5CVE-2026-3336 · Published Mar 2, 2026 · updated Mar 3, 2026

### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. ### Acknowledgement We would like to thank Joshua Rogers (https://joshua.hu/) of AISLE Research Team (https://aisle.com) for collaborating on this issue through the coordinated vulnerability disclosure process.

GitHub advisory

Affected versions

PackageAffectedFixed in
AWS-LC
Product
>= v1.41, < v1.69.0v1.69.0
Details and references

### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue. ### Acknowledgement We would like to thank Joshua Rogers (https://joshua.hu/) of AISLE Research Team (https://aisle.com) for collaborating on this issue through the coordinated vulnerability disclosure process.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)

More AWS advisories

All AWS
Advisory
CRL Distribution Point Scope Check Logic Error in AWS-LC
High7.4Mar 19
Defense-in-depth: Replaced eval() with safe parser in JumpStart search functionality
High8.4Mar 5
PKCS7_verify Signature Validation Bypass in AWS-LC
High7.5Mar 2
Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
Medium5.9Mar 2
Memory overallocation in aws-kms-tls-auth
Low3.7Mar 2
cli_history database does not restrict file permissions on Unix systems
Medium5.9Feb 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.