🛡️ GHSA-394x-vwmw-crm3 — aws-lc-sys

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-155 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

AWS-LC X.509 Name Constraints Bypass via Wildcard/Unicode CN

Summary

AWS-LC is an open-source, general-purpose cryptographic library.

Impact

A logic error in CN (Common Name) validation allows certificates with wildcard or raw UTF-8 Unicode CN values to bypass name constraints enforcement. The cn2dnsid function does not recognize these CN patterns as valid DNS identifiers, causing NAME_CONSTRAINTS_check_CN to skip validation. However, X509_check_host accepts these CN values when no dNSName SAN is present, allowing certificates to bypass name constraints while still being used for hostname verification.

Customers of AWS services do not need to take action. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.

Impacted versions:

  • aws-lc-sys >= v0.32.0, < v0.39.0

Patches

The patch is included in aws-lc-sys v0.39.0.

Workarounds

Applications that set X509_CHECK_FLAG_NEVER_CHECK_SUBJECT to disable CN fallback are not affected. Applications that only encounter certificates with dNSName SANs (standard for public WebPKI) are also not affected.

Otherwise, there is no workaround and applications using aws-lc-sys should upgrade to the most recent releases of aws-lc-sys.

References

If you have any questions or comments about this advisory, we ask that you contact AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting/) or directly via email to [[email protected]](mailto:[email protected]). Please do not create a public GitHub issue.

Credits

Oleh Konko from 1seal (https://1seal.org/)

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality none, integrity high, availability none.

Weakness class

GHSA-394x-vwmw-crm3 is classified as CWE-155: Improper Neutralization of Wildcards or Matching Symbols. The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as wildcards or matching symbols when they are sent to a downstream component.

Affected software

GHSA-394x-vwmw-crm3 is recorded against 1 package.

  • aws-lc-sys

Timeline and source

Published on 20 March 2026 and last revised on 24 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Package)
rustsec.org (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CWE CWE-155
Public Exploit ✅ No
Source OSV
Published 2026-03-20
Updated 2026-08-20
Modified 2026-03-24
Fix URL N/A

Affected Packages

Software From version Fixed in
aws-lc-sys

Similar Threats

Site Security Check

Is aws-lc-sys part of your stack?

GHSA-394x-vwmw-crm3 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesGitHub AdvisoryGitHub Advisory Undated