VDB

CVE-2025-14764

CVE-2025-14764 PUBLISHED CVSS 5.300000190734863 MEDIUM

Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.

EPSS 0.11% · 1.3th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.11%
1.3th percentile

Affected Products

VendorProductVersions
github.comaws/amazon-s3-encryption-client-go/v30
AWSS3 Encryption Client for Go4.0

Timeline

  • Dec 16, 2025 CVE ID Reserved
  • Dec 17, 2025 CVE Published
  • Dec 17, 2025 PoC Published
  • Dec 17, 2025 CVE Updated
  • Dec 18, 2025 EPSS Score
  • Dec 22, 2025 EPSS Score
  • Dec 26, 2025 EPSS Score
  • Dec 30, 2025 EPSS Score
  • Jan 3, 2026 EPSS Score
  • Jan 7, 2026 EPSS Score
  • Jan 11, 2026 EPSS Score
  • Jan 15, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›