CVE-2025-14764
Last modified
CVE-2025-14764 is a medium-severity vulnerability rated 6/10 on the CVSS scale. Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.. EPSS estimates a 0.09% chance of exploitation in the next 30 days.
Description
Missing cryptographic key commitment in the Amazon S3 Encryption Client for Go may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue, upgrade Amazon S3 Encryption Client for Go to version 4.0 or later.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-14764?
How severe is CVE-2025-14764?
How do I fix CVE-2025-14764?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-14758Incorrect configuration of replication security in the Maria…6.5
- CVE-2025-14759Missing cryptographic key commitment in the Amazon S3 Encryp…6
- CVE-2025-14760Missing cryptographic key commitment in the AWS SDK for C++ …6
- CVE-2025-14761Missing cryptographic key commitment in the AWS SDK for PHP …6
- CVE-2025-14762Missing cryptographic key commitment in the AWS SDK for Ruby…6
- CVE-2025-14763Missing cryptographic key commitment in the Amazon S3 Encryp…6
- CVE-2025-14765Use after free in WebGPU in Google Chrome prior to 143.0.749…8.8
- CVE-2025-14766Out of bounds read and write in V8 in Google Chrome prior to…8.8
- CVE-2025-14767The WPC Badge Management for WooCommerce plugin for WordPres…5.5
- CVE-2025-14769In some cases, the `tcp-setmss` handler may free the packet …7.5
- CVE-2025-1477An issue has been discovered in GitLab CE/EE affecting all v…7.5
- CVE-2025-14770The Shipping Rate By Cities plugin for WordPress is vulnerab…7.5
Are you affected by CVE-2025-14764?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
