GO-2023-2385
Dashboard / Vulnerabilities / GO-2023-2385
GO-2023-2385
Published: 2 Jan 2024Last Modified: 7 Jul 2026
Summary: Insufficient entropy in AES-256-CBC in github.com/pubnub/go
Details: There is insufficient entropy in the implementation of the AES-256-CBC cryptographic algorithm. The provided encrypt functions are less secure when hex encoding and trimming are applied, leaving half of the bits in the key always the same for every encoded message or file. Users are encouraged to migrate to the new crypto package introduced in v7.2.0.
References: https://github.com/advisories/GHSA-5844-q3fc-56rh, https://github.com/pubnub/go/commit/428517fef5b901db7275d9f5a75eda89a4c28e08
Affected packages
Package
Name: github.com/pubnub/go
Purl: pkg:golang/github.com/pubnub/go
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
