CVE-2026-3336
Improper certificate validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass certificate chain verification when processing
PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.
There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://crates.io/crates/aws-lc-sys, https://rustsec.org/advisories/RUSTSEC-2026-0046.html, https://aws.amazon.com/security/security-bulletins/2026-005-AWS, https://github.com/aws/aws-lc-rs/security/advisories/GHSA-vw5v-4f2q-w9xf