Incorrect Implementation of Authentication Algorithm Affecting github.com/tillitis/tkeyclient package, versions <1.3.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMTILLITISTKEYCLIENT-15763537
  • published25 Mar 2026
  • disclosed17 Mar 2026
  • creditUnknown

Introduced: 17 Mar 2026

CVE-2026-32953  (opens in a new tab)
CWE-303  (opens in a new tab)

How to fix?

Upgrade github.com/tillitis/tkeyclient to version 1.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Implementation of Authentication Algorithm due to an error in the protocol implementation when handling the User Supplied Secret (USS) digest in the LoadApp function. An attacker can cause the Compound Device Identifier (CDI) to be generated as if no USS was provided by supplying a USS digest that begins with a zero byte, resulting in the same key material as if the USS was omitted.

Note: This is only exploitable if the provided USS digest starts with a zero byte.

Workaround

This vulnerability can be mitigated by choosing a different USS that does not result in a digest beginning with a zero byte.

CVSS Base Scores

version 4.0
version 3.1