highCVSS 7.5Vulnerability

GHSA-vw5v-4f2q-w9xf

### Summary AWS-LC is an open-source, general-purpose cryptographic library. ### Impact Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. #### Impacted versions: aws-lc-sys versions: >= 0.24.0, < 0.38.0 ### Patches The patch is included in v0.38.0 ### Workarounds There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys. ### Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue. ### Acknowledgement AWS-LC would like to thank Joshua Rogers (https://joshua.hu/) for collaborating on this issue through the coordinated vulnerability disclosure process.

Properties

ghsa_id
GHSA-vw5v-4f2q-w9xf
severity
high
summary
AWS-LC has PKCS7_verify Certificate Chain Validation Bypass
cvss_score
7.5
cve_id
GHSA-vw5v-4f2q-w9xf
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-03-03T20:08:24Z
source_url
https://github.com/advisories/GHSA-vw5v-4f2q-w9xf
ghsa_updated
2026-03-20T21:31:18Z

Related Entities (3)

AFFECTS (1)

[Software]rust/aws-lc-sys

HAS_WEAKNESS (1)

[Weakness]Improper Certificate Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-vw5v-4f2q-w9xf (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal