PT-2026-23662 · Amazon Web Services · Aws-Lambda

Jakub Ciolek

·

Published

2026-03-06

·

Updated

2026-03-09

·

CVE-2026-27137

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions AWS Lambda (affected versions not specified)
Description A flaw exists in AWS Lambda base images utilizing stdlib. Specifically, when validating a certificate chain with multiple email address constraints that share common local portions but differ in domain portions, the constraints are not correctly applied. Only the last constraint in the chain is considered during verification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2026-27137
GO-2026-4599
OPENSUSE-SU-2026:10299-1

Affected Products

Aws-Lambda