VYPR

AWS Lc Fips Sys

by Amazon

CVEs (1)

  • CVE-2026-3337MedMar 2, 2026
    risk 0.38cvss 5.9epss 0.01

    Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and…