Spoofing attack in AWS SDK for PHP - CVE-2025-14761
Published: December 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to a single ciphertext can be decrypted into 2 different plaintexts by using different encryption keys. A remote user with permission to upload a new instruction file to the S3 bucket to replace the existing instruction file can create a rouge EDK key and force the application to use it in any future attempts to decrypt the underlying encrypted message with the S3EC.
Affected software
Moodle
Amazon AWS SDK
AWS SDK for PHP
Amazon Web Services (AWS) Toolbox
How to mitigate CVE-2025-14761
AWS SDK for PHP - update to 3.368.0
Moodle - addressed in versions 4.5.11, 5.0.7, 5.1.4
Amazon Web Services (AWS) Toolbox - addressed in versions 11.0.4, 12.0.2