GHSA-w67g-5rqw-f597

    Dashboard / Vulnerabilities / GHSA-w67g-5rqw-f597

    GHSA-w67g-5rqw-f597

    Published: 24 Aug 2026Last Modified: 10 Sept 2026
    Aliases:

    Summary: Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

    Details: gorilla/websocket used `math/rand` (cryptographically weak pseudo-random number generator) to generate WebSocket frame mask keys prior to commit d67f4185. WebSocket masking keys MUST be unpredictable to prevent frame content injection attacks. math/rand produces deterministic output when seeded with a known value, enabling an attacker to predict or recover mask keys and inject content into WebSocket connections. **Type:** Use of Cryptographically Weak Pseudo-Random Number Generator **Fix:** Replaced math/rand with crypto/rand (commit d67f4185, released in v1.5.3) **Credit:** bounty-hunter v6.0 silent-fix detection

    Affected packages

    Package

    Name: github.com/gorilla/websocket

    Purl: pkg:golang/github.com/gorilla/websocket

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.5.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High