aws-encryption-sdk vulnerabilities
CVEs whose affected-version data names the aws-encryption-sdk package (maven, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-6550Medium· 4.7AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
AWS Encryption SDK for Python: Key commitment policy bypass via shared key cache
▾ Sunlitaws-encryption-sdk · aws-encryption-sdkEPSS 0.10%via OSV
CVE-2020-8897High· 8.1Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness
Security issues in AWS KMS and AWS Encryption SDKs: in-band protocol negotiation and robustness
▾ Twilightamazonaws · com.amazonaws:aws-encryption-sdk-javaEPSS 0.40%via OSV