216.73.217.22

CVE-2026-47074

· Published 28/05/2026 10:16 · Modified 29/05/2026 15:29

Labels: CVE-2026-47074 2026-05-286b3ad84c-e1a6-4bf7-a703-f496b71e49dbCVE-2026-47074CWE-295

Essential information

Published
28/05/2026 10:16
Modified
29/05/2026 15:29
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/ex_aws/sns.ex, lib/ex_aws/sns/public_key_cache.ex and program routines 'Elixir.ExAws.SNS':verify_message/1, 'Elixir.ExAws.SNS.PublicKeyCache':get/1. 'Elixir.ExAws.SNS':verify_message/1 fetches the signing certificate from the SigningCertURL field of the incoming SNS message without validating that the URL uses HTTPS or that the host matches an AWS-owned SNS certificate domain. An unauthenticated attacker who can POST to an endpoint that calls verify_message/1 can supply an attacker-controlled SigningCertURL, sign a forged SNS message with their own key, and cause the function to return :ok, completely bypassing SNS signature verification. This issue affects ex_aws_sns: from 2.0.1 before 2.3.5.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
NVD
View on NVD

Affected products (CPE)

ProductCPE
ex-aws / ex aws sns cpe:2.3:a:ex-aws:ex_aws_sns:2.0.1-2.3.4:*:*:*:*:*:*:*
elixir / exaws sns cpe:2.3:a:elixir:exaws_sns:*:*:*:*:*:*:*:*

References