{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-3338", "assignerOrgId": "ff89ba41-3aa1-4d27-914a-91399e9639e5", "state": "PUBLISHED", "assignerShortName": "AMZN", "dateReserved": "2026-02-27T15:16:29.281Z", "datePublished": "2026-03-02T21:22:41.954Z", "dateUpdated": "2026-07-15T01:06:33.422Z" }, "containers": { "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "AWS-LC", "vendor": "AWS", "versions": [ { "lessThan": "1.69.0", "status": "affected", "version": "1.41.0", "versionType": "custom" } ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "
Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.