aws.amazon.comVendor advisory
https://aws.amazon.com/security/security-bulletins/2026-017-aws CVE-2026-6550
MEDIUM
Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
Record summary
CVE-2026-6550 has a selected CVSS score of 5.7 (medium).
Description
Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 20, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AWS Encryption SDK for PythonBrowse AWS / AWS Encryption SDK for PythonDefault status: unaffected | CVE List | 2 to ≤ 2.5.1 | affected |
| 3 to ≤ 3.3.0 | affected | ||
| 4 to ≤ 4.0.4 | affected | ||
aws-encryption-sdkBrowse PyPI / aws-encryption-sdk | GitHub Advisory | 2.0.0 to < 3.3.1 · Fixed in 3.3.1 | affected |
| 4.0.0 to < 4.0.5 · Fixed in 4.0.5 | affected |
References
7github.com
https://github.com/aws/aws-encryption-sdk-python github.compatch
https://github.com/aws/aws-encryption-sdk-python/releases/tag/v3.3.1 github.compatch
https://github.com/aws/aws-encryption-sdk-python/releases/tag/v4.0.5 github.comThird-party advisory
https://github.com/aws/aws-encryption-sdk-python/security/advisories/GHSA-v638-38fc-rhfv github.com
https://github.com/google/security-research/security/advisories/GHSA-wqgp-vphw-hphf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6550