Vulnerabilities
CVE-2025-14764 - Amazon S3 Encryption Client for Go Key Commitment Weakness
CVE ID : CVE-2025-14764 Published : Dec. 17, 2025, 8:20 p.m. | 32 minutes ago Description : The Amazon S3 Encryption Client for Go is an open-source client-side encryption library used to facilitate writing and reading encrypted records to S3. Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an
CVE Details
CVE ID
Published
Dec. 17, 2025
Source: Telegram CVE Monitor