Skip to content
AWSGHSA-jchq-39cv-q4wj

PKCS7_verify Signature Validation Bypass in AWS-LC

High7.5CVE-2026-3338 · Published Mar 2, 2026

### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### Impacted versions From v1.41.0 through v1.68.0. ### Patches The patch is included in v1.69.0. ### Workarounds There is no workaround. Applications using AWS-LC should upgrade to the most recent release of AWS-LC. ### References If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
AWS-LC
Product
>= v1.41, < v1.69.0v1.69.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)

More AWS advisories

All AWS
Advisory
CRL Distribution Point Scope Check Logic Error in AWS-LC
High7.4Mar 19
Defense-in-depth: Replaced eval() with safe parser in JumpStart search functionality
High8.4Mar 5
Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
Medium5.9Mar 2
PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
High7.5Mar 2
Memory overallocation in aws-kms-tls-auth
Low3.7Mar 2
cli_history database does not restrict file permissions on Unix systems
Medium5.9Feb 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.