<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:58:39 +0000</lastBuildDate>
    <item>
      <title>CVE-2020-8897 — Robustness weakness in AWS KMS and Encryption SDKs</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2020-8897</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Amazon AWS SDK&lt;/p&gt;
&lt;p&gt;A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Amazon AWS SDK&lt;/p&gt;
&lt;p&gt;A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (X)ChaCha20Poly1305) used by the SDKs to encrypt messages, an attacker can craft a unique cyphertext which will decrypt to multiple different results, and becomes especially relevant in a multi-recipient setting. We recommend users update their SDK to 2.0.0 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2020-8897</guid>
    </item>
    <item>
      <title>GHSA-wqgp-vphw-hphf — Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wqgp-vphw-hphf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.amazonaws:aws-encryption-sdk-java, PyPI: aws-encryption-sdk&lt;/p&gt;
&lt;p&gt;Authors: Thai &amp;#34;[thaidn](https://twitter.com/xorninja)&amp;#34; Duong&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;The following security vulnerabilities was discovered and reported to Amazon, affecting AWS KMS and all versions of [AWS Encryption SDKs](https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/introduction.html) prior to version 2.0.0:&lt;/p&gt;
&lt;p&gt;* **Information leakage**: an attacker can create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption
* **Ciphertext forgery**: an attacker can create ciphertexts that are accepted by other users
* **Robustness**: an attacker can create ciphertexts that decrypt to different plaintexts for different users&lt;/p&gt;
&lt;p&gt;The first two bugs are somewhat surprising because they show that the ciphertext format can lead to vulnerabilities. These bugs (and the infamous [alg: &amp;#34;None&amp;#34;](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/) bugs in JWT) belong to a class of vulnerabilities called **in-band protocol negotiation**. This is the second time we’ve found in-band protocol negotiation vulnerabilities in AWS cryptography libraries; see this [bug](https://github.com/google/security-research/security/advisories/GHSA-7f33-f4f5-xwgw) in S3 Crypto SDK discovered by my colleague Sophie Schmieg.&lt;/p&gt;
&lt;p&gt;In JWT and S3 SDK the culprit is the algorithm field—here it is the key ID. Because the key ID is used to determine which decryption key to use, it can’t be meaningfully authenticated despite being under…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: com.amazonaws:aws-encryption-sdk-java, PyPI: aws-encryption-sdk&lt;/p&gt;
&lt;p&gt;Authors: Thai &amp;#34;[thaidn](https://twitter.com/xorninja)&amp;#34; Duong&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;The following security vulnerabilities was discovered and reported to Amazon, affecting AWS KMS and all versions of [AWS Encryption SDKs](https://docs.aws.amazon.com/encryption-sdk/latest/developer-guide/introduction.html) prior to version 2.0.0:&lt;/p&gt;
&lt;p&gt;* **Information leakage**: an attacker can create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption
* **Ciphertext forgery**: an attacker can create ciphertexts that are accepted by other users
* **Robustness**: an attacker can create ciphertexts that decrypt to different plaintexts for different users&lt;/p&gt;
&lt;p&gt;The first two bugs are somewhat surprising because they show that the ciphertext format can lead to vulnerabilities. These bugs (and the infamous [alg: &amp;#34;None&amp;#34;](https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/) bugs in JWT) belong to a class of vulnerabilities called **in-band protocol negotiation**. This is the second time we’ve found in-band protocol negotiation vulnerabilities in AWS cryptography libraries; see this [bug](https://github.com/google/security-research/security/advisories/GHSA-7f33-f4f5-xwgw) in S3 Crypto SDK discovered by my colleague Sophie Schmieg.&lt;/p&gt;
&lt;p&gt;In JWT and S3 SDK the culprit is the algorithm field—here it is the key ID. Because the key ID is used to determine which decryption key to use, it can’t be meaningfully authenticated despite being under…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wqgp-vphw-hphf</guid>
    </item>
  </channel>
</rss>
