GHSA-mpwr-8vm7-h73f: package pkcs12: Authentication bypass in Decode functions
Summary
Several functions in the pkcs12 package can incorrectly accept PKCS#12 files (a format for storing encrypted certificates and keys) that were encoded with the wrong password, because they fail to reject overly-short PBMAC1 keys (a cryptographic authentication code). This means an attacker could trick someone into accepting a malicious PKCS#12 file if that person decodes untrusted files and relies on password protection to verify authenticity.
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-mpwr-8vm7-h73f
First tracked: August 17, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 72%