github.com/mailgun/mailgun-go/v4 is vulnerable to Incorrect Use of Privileged APIs
18
Low Risk
Affected versions of this package incorrectly use the APIKey as the signature key in the VerifyWebhookSignature method instead of the intended WebhookSigningKey. This misconfiguration weakens the security of webhook verification, potentially allowing attackers to bypass signature checks and send unauthorized requests.
You are affected if you are using a version that falls within the vulnerable range.
github.com/mailgun/mailgun-go/v4 is vulnerable to Incorrect Use of Privileged APIs in versions 4.0.0 - 4.18.5.
Upgrade the github.com/mailgun/mailgun-go/v4 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant