Vulnerabilities
CVE-2026-3338 - PKCS7_verify Signature Validation Bypass in AWS-LC
CVE ID : CVE-2026-3338 Published : March 2, 2026, 9:22 p.m. | 26 minutes ago Description : Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...