THREAT OPS › Threat News › [GHSA] GHSA-mpwr-8vm7-h73f (medium) — package pkcs12: Authentication bypass in Decode functions
[GHSA] GHSA-mpwr-8vm7-h73f (medium) — package pkcs12: Authentication bypass in Decode functions
GHSA-mpwr-8vm7-h73f Severity: medium CVE: None
package pkcs12: Authentication bypass in Decode functions
`Decode`, `DecodeChain`, `DecodeTrustStore`, and `ToPEM` can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-34181cve
- https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181url
Original source: https://github.com/advisories/GHSA-mpwr-8vm7-h73f