CVE-2025-14763 - Amazon S3 Encryption Client for Java Cryptographic Key Commitment Vulnerability

CVE-2025-14763 - Amazon S3 Encryption Client for Java Cryptographic Key Commitment Vulnerability

CVE ID : CVE-2025-14763 Published : Dec. 17, 2025, 8:18 p.m. | 34 minutes ago Description : The S3 Encryption Client for Java is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3. Missing cryptographic key commitment in the Amazon S3 Encryption Client for Java may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an

CVE Details

Published
Dec. 17, 2025
Affected Product: Java

Source: Telegram CVE Monitor