CVE-2026-3337 | Amazon AWS-LC/AWS-LC-FIPS up to 1.68.x EVP CIPHER API EVP_aes_128_ccm/EVP_aes_192_ccm/EVP_aes_256_ccm timing discrepancy (GHSA-frmv-5gcm-jwxh / Nessus ID 300927)
A vulnerability, which was classified as problematic, has been found in Amazon AWS-LC and AWS-LC-FIPS up to 1.68.x. This issue affects the function EVP_aes_128_ccm/EVP_aes_192_ccm/EVP_aes_256_ccm of the component EVP CIPHER API. This manipulation causes observable timing discrepancy.
This vulnerability is tracked as CVE-2026-3337. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.