PST fail-closed + protobuf compatibility fix
details
- Finding IDs
- F-CEDAR-PST-ERRORCONSTRAINT-001
- Status
- fixed publicly
- Reported via
- security contact
- Note
- public fixes #2246 and #2247 merged on 2026-03-23. AWS stated no customer action was required because the affected paths needed two experimental flags enabled together and were not used in AWS authorization paths.
F-CEDAR-PST-ERRORCONSTRAINT-001: Access control. Serialization widens an invalid policy constraint to match all actions. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CEDAR-PST-ERRORCONSTRAINT-001
Security area (1seal assessment): Semantics. Serialization changes an invalid action constraint into a match-all constraint, so the decoded policy no longer means the original policy. The experimental-feature and deployment limits remain in the record. Reviewed 24 Sep 2026.