Skip to main navigation Skip to main content Skip to page footer

TYPO3-EXT-SA-2026-004: Vulnerability in bundled package in extension "Amazon AWS SDK" (aws)

Categories: Development Created by Torben Hansen

It has been discovered that the extension "Amazon AWS SDK" (aws) bundles a vulnerable version of “aws/aws-sdk-php“ which is susceptible to use of a Broken or Risky Cryptographic Algorithm.

Problem Description

The extension bundles the PHP package “aws/aws-sdk-php”, which contains a known Broken or Risky Cryptographic Algorithm vulnerability.

Solution

All versions of this extension that are known to be vulnerable will no longer be available for download from the TYPO3 Extension Repository, because the extension is outdated and unmaintained.

Please uninstall and delete the extension folder from your installation and search on the TYPO3 Extension Repository for alternative extensions.

Credits

Thanks to Michael Schams  for reporting the vulnerability.

General Advice

Follow the recommendations that are given in the TYPO3 Security Guide. Please subscribe to the typo3-announce mailing list.