highCVSS 7.5Vulnerability

GHSA-hfpc-8r3f-gw53

### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. #### Impacted versions: aws-lc-sys versions: >= 0.24.0, < 0.38.0 ### Patches The patch is included in v0.38.0 ### Workarounds There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. ### Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Properties

ghsa_id
GHSA-hfpc-8r3f-gw53
severity
high
summary
AWS-LC has PKCS7_verify Signature Validation Bypass
cvss_score
7.5
cve_id
GHSA-hfpc-8r3f-gw53
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-03-03T20:25:39Z
source_url
https://github.com/advisories/GHSA-hfpc-8r3f-gw53
ghsa_updated
2026-03-20T21:31:49Z

Related Entities (3)

AFFECTS (1)

[Software]rust/aws-lc-sys

HAS_WEAKNESS (1)

[Weakness]Improper Verification of Cryptographic Signature

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-hfpc-8r3f-gw53 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal