Skip to content

Authentication bypass in Decode functions

Low
AGWA published GHSA-mpwr-8vm7-h73f Jun 10, 2026

Package

gomod software.sslmate.com/src/go-pkcs12 (Go)

Affected versions

0.6.0, 0.7.0, 0.7.1

Patched versions

0.7.2

Description

Decode, DecodeChain, DecodeTrustStore, and ToPEM can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication can be tricked into accepting malicious PKCS#12 files. Users who only decode PKCS#12 files from trusted sources are not affected.

Thanks to Pavol Žáčik (Red Hat) and Alex Gaynor (Anthropic) for finding and reporting the same issue in OpenSSL (CVE-2026-34181).

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs