OVERVIEW CVE-2026-6550 is a cryptographic algorithm downgrade vulnerability in the AWS Encryption SDK for Python that affects versions prior to 3.3.1 and 4.0.5. The vulnerability resides in the caching layer and allows an authenticated local threat actor to bypass key commitment policy enforcement through manipulation of a shared key cache. This exploitation could result in ciphertext that decrypts to multiple different plaintexts, undermining the integrity guarantees of encrypted data. SEVERITY The vulnerability carries a CVSS 3.1 score of 4.7 (MEDIUM) with a local attack vector, high attack complexity, and low privilege requirements. The primary impact is to integrity, with no direct confidentiality or availability implications. The attack requires local access and authentication, limiting the threat actor pool to individuals with some level of system access. While the CVSS rating is moderate, the nature of the integrity compromise—allowing multiple valid plaintexts from a single ciphertext—represents a serious cryptographic weakness. EXPLOITATION STATUS There is no evidence of active exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the extremely low EPSS score of 0.000090 indicates minimal real-world exploitation activity. No public exploit code is currently available, and community attention remains minimal. However, organizations should prioritize patching as the vulnerability's cryptographic nature could make it attractive for sophisticated threat actors targeting high-value encrypted data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AWS | AWS Encryption SDK For Python | >= 2, <= 2.5.1, >= 3, <= 3.3.0, >= 4, <= 4.0.4CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.