Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-6550

4 месяца назад

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-v638-38fc-rhfv

3 месяца назад

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-6550

Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.

CVSS3: 4.7
0%
Низкий
4 месяца назад
github логотип
GHSA-v638-38fc-rhfv

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

CVSS3: 4.7
0%
Низкий
3 месяца назад

Уязвимостей на страницу