VYPR

PyPI package

aws-encryption-sdk

pkg:pypi/aws-encryption-sdk

Vulnerabilities (2)

  • CVE-2026-6550MedApr 20, 2026
    affected >= 2.0.0, < 3.3.1fixed 3.3.1

    Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertex

  • CVE-2020-8897Nov 16, 2020
    affected < 2.0.0fixed 2.0.0

    A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an