CVE-2026-3336
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.77% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- amazon/aws-lc-sys · amazon/aws libcrypto
- Source
- ff89ba41-3aa1-4d27-914a-91399e9639e5
References
- https://aws.amazon.com/security/security-bulletins/2026-005-AWS/Vendor Advisory
- https://github.com/aws/aws-lc/releases/tag/v1.69.0Release Notes
- https://github.com/aws/aws-lc/security/advisories/GHSA-cfwj-9wp5-wqvpVendor Advisory
- https://access.redhat.com/errata/RHSA-2026:5459
- https://access.redhat.com/security/cve/CVE-2026-3336
- https://bugzilla.redhat.com/show_bug.cgi?id=2444026
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3336.json
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.