HarborGuard / CVE
Back to search
HIGHCVE-2026-3336Published Modified CNA AMZN

CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
1.69.0
Affected Products
1

Fix available

1.69.0
Patch commits
Affected packages
  • AWS / AWS-LC
    < 1.69.0 (from 1.41.0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC | HarborGuard CVE