Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.
To mitigate this issue, upgrade AWS SDK for C++ to version 1.11.712 or later
[
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-0f271fae",
"target": {
"file": "generated/tests/iot-gen-tests/IoTIncludeTests.cpp"
},
"digest": {
"line_hashes": [
"263942582093231990375499137466436303384",
"166566496732055237791042541928485948406",
"12962983753337839925128801551146877963",
"280682201877747192668540279471430766021",
"32121170553145278628156536206374231519",
"42524992478416929594989580749747927377",
"167428321668896350251721059924509984729",
"98980886203383205192515482375167520560",
"230431629278862029623100175891713577041",
"194610656511917144596801197770309585430",
"147243391624291835870769971241717597060",
"197022621464536474627748793264181525185",
"134286534427759030837400756309132681822",
"80479350069992951783756454243711901999"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-15b8c0c5",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/include/aws/timestream-influxdb/TimestreamInfluxDBClient.h"
},
"digest": {
"line_hashes": [
"248192581955863929254864402715424143284",
"114195379626459160080727404526903548603",
"43175757803330470266709783888564489210"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-1725c690",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/include/aws/timestream-influxdb/model/ClusterStatus.h"
},
"digest": {
"line_hashes": [
"289472130351447379756741931511953044853",
"86578534637063006535231178106344365934",
"271580926162918857339290881535579236797",
"258632404919339144780767260221540769377"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-25e62b7a",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/GetCommandResult.cpp"
},
"digest": {
"line_hashes": [
"12718085981434994992663236129831300455",
"197591352220584850755615342737671538686",
"306158009486701720523497500158862536646",
"144203168202994375585334020460277545504"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-26f24380",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/CommandParameter.cpp",
"function": "operator="
},
"digest": {
"function_hash": "131819109068821816886612984565587166927",
"length": 542.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-27d58439",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/include/aws/iot/model/GetCommandResult.h"
},
"digest": {
"line_hashes": [
"98750131216589401843833426521932901365",
"186712801093669330877158969253998468163",
"83900458050417024499139021897829124302",
"66572503879909874545212601801458482014",
"43658876908229434462831492986392229994",
"97060762991277594537211845585216793994",
"280420421619297436156499585773882364181",
"323967393838824128998656702804956499013",
"234837417760706674844325338054873787475",
"298914218330187450891309189288715379162",
"227347124407161568650616137208838992742",
"330167550506736938026229910575523465760",
"176006424459387097662464079439486457292",
"320236300300547090931952418040992921888"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-2a756342",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/Status.cpp"
},
"digest": {
"line_hashes": [
"195233105893490839721173708886904507689",
"330811924642479913287312045001784677917",
"214670891056990612442762525996395134556",
"95784708822537181686104832777314412918",
"154148874834353228764491311164407025634",
"337557188424408296501965811428662196690",
"83685914762059047839424053960427331489",
"75483139788294664658551101543918703455",
"233098303240682277091005300201904234180",
"270875291573023904686340880839099201811",
"125589729193278051036515659588590576796",
"32493332067818659069558630034659854696"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-2e628ffa",
"target": {
"file": "generated/tests/timestream-influxdb-gen-tests/TimestreamInfluxDBIncludeTests.cpp"
},
"digest": {
"line_hashes": [
"258342832185261364973948855736695050528",
"140547294096391269121401365261862877772",
"272270417554353213372018470413312473791",
"164302792716346867255583223433863766064"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-34722f37",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/ClusterStatus.cpp",
"function": "GetNameForClusterStatus"
},
"digest": {
"function_hash": "77125204043853220976215413028384750986",
"length": 568.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-3b40b294",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/include/aws/iot/model/CommandParameter.h"
},
"digest": {
"line_hashes": [
"2974832263064388728912649721985060434",
"306292670391138321051641563249171783554",
"234669068474578233357962344784641980826",
"208931880998428987303875077944613344450",
"284879368217363286273638692483264533789",
"20961301251900397977869315900648982948",
"103238352436816981149539087701138649361",
"625863426684332778979513873437883312",
"116953156721144511543765927615878801901",
"59334085971972075601441985166730728289",
"88067196857349166106693606818137815562",
"179107817238167302533408398696845321251",
"159485426081405115530687378513569789361",
"114944009923794118616567547626214548458",
"335483922785504966562746543860782919403",
"217030913451626047392316518231622254234",
"176195871518675278160105371446329177419",
"123684674081358929493127652596890102223",
"102802668912880735139944290468815698537"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-4068c0af",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/CreateCommandRequest.cpp"
},
"digest": {
"line_hashes": [
"313725503220846060732479337189115411456",
"153143529327396765965318518236088114471",
"8329809579696959865568999349678042702"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-64297a43",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/ClusterStatus.cpp"
},
"digest": {
"line_hashes": [
"244826393134531655403066061878762150923",
"11035035445291729327982225276167085839",
"76185922985518552875632395806890316050",
"39372531846585668755917530185568640778",
"317593780868664762734996643735341363312",
"99395717425934732912403458885430044550",
"10828455499959929238317619626972153492",
"314094116256041061763776491484417616431",
"329408629394635172945740961527156625513",
"171905062111137372526871198379927476822",
"290931610994165706135476913107706175670",
"32493332067818659069558630034659854696"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-67fb87a0",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/ClusterStatus.cpp",
"function": "GetClusterStatusForName"
},
"digest": {
"function_hash": "331266208123086928285582494281575094191",
"length": 721.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-74e07cf0",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/Status.cpp",
"function": "GetStatusForName"
},
"digest": {
"function_hash": "229355796126931107046295467655359607261",
"length": 975.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-7945c137",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/include/aws/iot/model/CreateCommandRequest.h"
},
"digest": {
"line_hashes": [
"98750131216589401843833426521932901365",
"78219807940979683016961506007415707294",
"61954737499170133108125656803163882257",
"118813858579928041979671274835463144432",
"332993893654094955534124468316024868172",
"124030845459771368642237280375310180920",
"303468727530973236944051064131042316294",
"91074378293827931876614978995122091077",
"292092962487097004053941940511542038024",
"151991717329423123604268717312459284301",
"102695484375188227717791470860862275245",
"200749043933216007526716124220916025015",
"228937937996006084730951814502139965972",
"272086797549478710388289013008315947533",
"320962958228381991415833953444481158941",
"131523762045265532610052876643761980252",
"226732995303994459184976214473200689178",
"307155445675025613792833273170768390792",
"185976238824704217432784296241816088644",
"2922698571274921086907624206783658225"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-906d094c",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/CommandParameter.cpp"
},
"digest": {
"line_hashes": [
"7220963206041730723566977220069432522",
"4243170981151204164867817858639831112",
"108848928676808285064238918831493170155",
"97924262384491574916974253615021260359",
"283523874739445764391103857579372919916",
"56904617571695508233822945883827118752",
"304074069727005378408722045860318014446",
"36863210271233152990099545112801380651",
"246741320462317805496110659532941408794",
"291217667914613372698916068681589944625",
"12520951850261728429055412935697262173",
"136504955153170179571147940130835386763",
"31196171028072444280534372038468966590",
"78146176126184930511701104661018618905"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-94cb6d5b",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/GetCommandResult.cpp",
"function": "operator="
},
"digest": {
"function_hash": "265584433103453953086431210416348699437",
"length": 2065.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-99cd7ff6",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/model/Status.cpp",
"function": "GetNameForStatus"
},
"digest": {
"function_hash": "134371120341887808400071962845310655006",
"length": 765.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-a509865e",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/CommandParameter.cpp",
"function": "CommandParameter::Jsonize"
},
"digest": {
"function_hash": "307987794928320425738156060231282867358",
"length": 416.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-a569a75b",
"target": {
"file": "generated/src/aws-cpp-sdk-iot/source/model/CreateCommandRequest.cpp",
"function": "CreateCommandRequest::SerializePayload"
},
"digest": {
"function_hash": "266227205534834924065607817706169757901",
"length": 1143.0
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-d03856ad",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/include/aws/timestream-influxdb/TimestreamInfluxDBServiceClientModel.h"
},
"digest": {
"line_hashes": [
"201212362728084219059252495688426594261",
"80831551279336449035442155405115110891",
"151489257765110988011655769901912006254",
"235592623464207012607248901329883544961",
"259206994795912408519937730465134196247",
"39743287565639588245124534210276753412",
"238758171772368849250034490775609028633",
"81655139072165465617327121654437326868",
"109987179721173531021706965016813838873",
"195738309365699191763481655785012113078",
"131090883218868758476646888761761492418",
"89051176458189744772313077019057102992",
"86313833491007669373824765576214489344",
"90113454341658463214287268415778113556",
"135463309433979586575353640824960115175",
"35371807439515728405621651618315576147",
"221465196271652923756435329026781791244",
"154001786803564462575993827238376358407",
"233495986296282881002572711245437310169",
"238029060663257008010109701665767878210"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-db8caef5",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/include/aws/timestream-influxdb/model/Status.h"
},
"digest": {
"line_hashes": [
"317721965679174265426818956931181429257",
"113750466998744184640966366885495969129",
"256250800373064196822930220330398256314",
"159054640584550103341249934294169790968"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"source": "https://github.com/aws/aws-sdk-cpp/commit/4aca5630ba6e49869a0f173f9439ae73722d4558",
"id": "CVE-2025-14760-ded5820a",
"target": {
"file": "generated/src/aws-cpp-sdk-timestream-influxdb/source/TimestreamInfluxDBClient.cpp"
},
"digest": {
"line_hashes": [
"15696464725315444605223372522702571565",
"225386032512075762699139052860511816166",
"296744839597988092316077210483948195826",
"210183615257170773421926698023500336252",
"229799933643009851094793792444986313811",
"322830539303248458519263272060264610264",
"223416526485541281606204787822223927238"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14760.json"