---
id: CVE-2025-14762
title: >-
  Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user
  with write access to the S3 bucket to introduce a new EDK that decrypts to
  different plaintext when the encrypted data key is stored in an "instruction
  file" i…
summary: >-
  Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user
  with write access to the S3 bucket to introduce a new EDK that decrypts to
  different plaintext when the encrypted data key is stored in an "instruction
  file" i…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-327
published: '2025-12-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14762'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/AWS-2025-032/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/aws/aws-sdk-ruby/security/advisories/GHSA-2xgq-q749-89fq
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://rubygems.org/gems/aws-sdk-s3/versions/1.208.0'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
epss: 0.00207
epssPercentile: 0.09706
ingestedAt: '2026-09-30T23:29:32.498Z'
---

## Overview

Missing cryptographic key commitment in the AWS SDK for Ruby may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.


To mitigate this issue, upgrade AWS SDK for Ruby to version 1.208.0 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
