Skip to content

Conversation

@jdwyah
Copy link
Contributor

@jdwyah jdwyah commented Oct 7, 2025

Description

    Currently the OpenSSL bindings do not raise an error if auth_tag is
    truncated, which would allow an attacker to easily forge it. See
    https://github.com/ruby/openssl/issues/63

Testing & Validation

Should be no end user facing change

@jdwyah jdwyah force-pushed the jd/sec-ssl-truncation branch from a21982e to b0ad318 Compare October 7, 2025 12:18
Copy link
Contributor

@mjfaga mjfaga left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

terrific. thanks

@jdwyah jdwyah merged commit dac3fc6 into main Oct 7, 2025
7 of 8 checks passed
@jdwyah jdwyah deleted the jd/sec-ssl-truncation branch October 7, 2025 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants