PT-2025-51885 · Amazon · Amazon S3 Encryption Client For Go

Published

2025-12-17

·

Updated

2026-01-06

·

CVE-2025-14764

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Amazon S3 Encryption Client for Go versions prior to 4.0
Description A missing cryptographic key commitment in the Amazon S3 Encryption Client for Go could allow a user with write access to an S3 bucket to introduce a new EDK (Encrypted Data Key) that decrypts to different plaintext. This is possible when the encrypted data key is stored in an instruction file instead of S3’s metadata record.
Recommendations Upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-14764
GHSA-3G75-Q268-R9R6
GO-2025-4250
SUSE-SU-2026:0037-1

Affected Products

Amazon S3 Encryption Client For Go