PKCS7_verify Signature Validation Bypass in AWS-LC
High7.5CVE-2026-3338 · Published Mar 2, 2026
### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| AWS-LC Product | >= v1.41, < v1.69.0 | v1.69.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 19 | CRL Distribution Point Scope Check Logic Error in AWS-LC | High7.4 | 1.71.0+1 more |
| Mar 5 | Defense-in-depth: Replaced eval() with safe parser in JumpStart search functionality | High8.4 | 3.4.0 |
| Mar 2 | Timing Side-Channel in AES-CCM Tag Verification in AWS-LC | Medium5.9 | v1.69.0+1 more |
| Mar 2 | PKCS7_verify Certificate Chain Validation Bypass in AWS-LC | High7.5 | v1.69.0 |
| Mar 2 | Memory overallocation in aws-kms-tls-auth | Low3.7 | 0.0.3 |
| Feb 25 | cli_history database does not restrict file permissions on Unix systems | Medium5.9 | 1.44.37+1 more |