CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python
Bulletin ID: 2026-017-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/20 12:45 PM PDT Description: AWS Encryption SDK (ESDK) for Python is a client-side encryption library. We identified CVE-2026-6550, which describes an issue with a key commitment policy bypass via shared key cache. Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and before version 4.0.5 might allow an authenticated local threat actor to bypass key commitment policy enforcement via a shared key cache, resulting in ciphertext that can be decrypted to multiple different plaintexts. Impacted versions: - From 2.0 to 2.5.1 - From 3.0 to 3.3.0 - From 4.0 to 4.0.4 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- A key commitment policy bypass via shared key cache may allow an authenticated local threat actor to bypass key commitment policy enforcement.
- Who is affected
- Authenticated users of AWS Encryption SDK for Python versions in the specified range.
- Urgency
- Remediation is important to prevent unauthorized decryption of ciphertext.
- Action
- Update to a version of AWS Encryption SDK for Python that addresses this issue.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch AWS Encryption SDK for Python
Get an email when a new AWS Encryption SDK for Python advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-017-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-65500.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-6550 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for - Key commitment
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-38474: GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a B…nvd · 2026-08-25
- unknownCVE-2026-38473: A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) comm…nvd · 2026-08-25
- unknownCVE-2026-38472: A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86…nvd · 2026-08-25
- unknownCVE-2026-38470: A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall…nvd · 2026-08-25
- unknownCVE-2026-38469: A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) …nvd · 2026-08-25
- unknownCVE-2026-38468: A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterW…nvd · 2026-08-25
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20