GHSA-mpwr-8vm7-h73f: Input Validation

Published Aug 17, 2026
·
Updated

Decode, DecodeChain, DecodeTrustStore, and ToPEM can incorrectly accept PKCS#12 files which were encoded with the wrong password, due to a failure to reject excessively-short PBMAC1 keys. Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication can be tricked into accepting malicious PKCS#12 files. Users who only decode PKCS#12 files from trusted sources are not affected.

Thanks to Pavol Žáčik (Red Hat) and Alex Gaynor (Anthropic) for finding and reporting the same issue in OpenSSL (CVE-2026-34181).

Affected Software

1 affected componentFixes available
go/software.sslmate.com/src/go-pkcs12>=0.6.0<0.7.2
0.7.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/software.sslmate.com/src/go-pkcs12 to a version that resolves this vulnerability.

    Fixed in 0.7.2

Event History

Aug 17, 2026
Advisory Published
via GitHub·09:56 PM
Data Sourced
via GitHub·09:56 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of GHSA-mpwr-8vm7-h73f?

The severity of GHSA-mpwr-8vm7-h73f is rated at 37, indicating a significant risk.

2

How do I fix GHSA-mpwr-8vm7-h73f?

To fix GHSA-mpwr-8vm7-h73f, ensure that you validate the integrity of PKCS#12 files and avoid decoding files from untrusted sources.

3

What vulnerabilities are associated with GHSA-mpwr-8vm7-h73f?

GHSA-mpwr-8vm7-h73f is associated with improper validation of PBMAC1 keys in PKCS#12 files.

4

What are the implications of GHSA-mpwr-8vm7-h73f?

The implications of GHSA-mpwr-8vm7-h73f include potential unauthorized access if untrusted PKCS#12 files are decoded using incorrect passwords.

5

What components are affected by GHSA-mpwr-8vm7-h73f?

GHSA-mpwr-8vm7-h73f affects the Decode, DecodeChain, and DecodeTrustStore functions in the go-pkcs12 library.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203