GHSA-hfpc-8r3f-gw53
### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. #### Impacted versions: aws-lc-sys versions: >= 0.24.0, < 0.38.0 ### Patches The patch is included in v0.38.0 ### Workarounds There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. ### Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.
Properties
- ghsa_id
- GHSA-hfpc-8r3f-gw53
- severity
- high
- summary
- AWS-LC has PKCS7_verify Signature Validation Bypass
- cvss_score
- 7.5
- cve_id
- GHSA-hfpc-8r3f-gw53
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T20:25:39Z
- source_url
- https://github.com/advisories/GHSA-hfpc-8r3f-gw53
- ghsa_updated
- 2026-03-20T21:31:49Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph