THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mpwr-8vm7-h73f (medium) — package pkcs12: Authentication bypass in Decode functions

[GHSA] GHSA-mpwr-8vm7-h73f (medium) — package pkcs12: Authentication bypass in Decode functions

highgithub_advisoriesPublished 2026-08-17

GHSA-mpwr-8vm7-h73f Severity: medium CVE: None

package pkcs12: Authentication bypass in Decode functions

`Decode`, `DecodeChain`, `DecodeTrustStore`, and `ToPEM` can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mpwr-8vm7-h73f