Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts.
To remediate this issue, users should upgrade to version 3.3.1, 4.0.5 or above.
References
Configurations
No configuration.
History
20 Apr 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 20:16
Updated : 2026-04-21 16:20
NVD link : CVE-2026-6550
Mitre link : CVE-2026-6550
CVE.ORG link : CVE-2026-6550
JSON object : View
Products Affected
No product.
CWE
CWE-757
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
