Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6550

20
FAUCET Score

OVERVIEW CVE-2026-6550 is a cryptographic algorithm downgrade vulnerability in the AWS Encryption SDK for Python that affects versions prior to 3.3.1 and 4.0.5. The vulnerability resides in the caching layer and allows an authenticated local threat actor to bypass key commitment policy enforcement through manipulation of a shared key cache. This exploitation could result in ciphertext that decrypts to multiple different plaintexts, undermining the integrity guarantees of encrypted data. SEVERITY The vulnerability carries a CVSS 3.1 score of 4.7 (MEDIUM) with a local attack vector, high attack complexity, and low privilege requirements. The primary impact is to integrity, with no direct confidentiality or availability implications. The attack requires local access and authentication, limiting the threat actor pool to individuals with some level of system access. While the CVSS rating is moderate, the nature of the integrity compromise—allowing multiple valid plaintexts from a single ciphertext—represents a serious cryptographic weakness. EXPLOITATION STATUS There is no evidence of active exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and the extremely low EPSS score of 0.000090 indicates minimal real-world exploitation activity. No public exploit code is currently available, and community attention remains minimal. However, organizations should prioritize patching as the vulnerability's cryptographic nature could make it attractive for sophisticated threat actors targeting high-value encrypted data.

Impacted Technologies

VendorProductVersion(s)CPE
AWSAWS Encryption SDK For Python
>= 2, <= 2.5.1, >= 3, <= 3.3.0, >= 4, <= 4.0.4CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 4.0

5.7MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.10%
Probability of exploitation in next 30 days
EPSS Percentile
0.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0010 is in the 11th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

pippatch availablevia ghsa
Product: aws-encryption-sdkFixed in: 3.3.1
pippatch availablevia ghsa
Product: aws-encryption-sdkFixed in: 4.0.5

Vendor Advisories (1)

pipGHSA-v638-38fc-rhfvmedium

AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache

Apr 24, 2026

References

aws.amazon.com / security/security-bulletins/2026-017-aws
github.com / aws/aws-encryption-sdk-python/releases/tag/v3.3.1
github.com / aws/aws-encryption-sdk-python/releases/tag/v4.0.5
github.com / aws/aws-encryption-sdk-python/security/advisories/GHSA-v638-38fc-rhfv