CVE Vulnerabilities

CVE-2026-3336

Improper Certificate Validation

Published: Mar 02, 2026 | Modified: Mar 11, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.

Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Aws-lc-sysAmazon0.24.0 (including)0.38.0 (excluding)
Aws_libcryptoAmazon1.41.0 (including)1.69.0 (excluding)

Potential Mitigations

References