Intel

AIKIDO-2025-10197

github.com/getsops/sops/v3 is vulnerable to Observable Timing Discrepancy

Observable Timing Discrepancy Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 1, 2025

47

Medium Risk

This Affects:

GOgithub.com/getsops/sops/v3
3.0.0 - 3.9.4
Fixed in 3.10.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package exhibit an observable timing discrepancy due to duplicated vulnerable code from github.com/hashicorp/vault (CVE-2023-25000). HashiCorp Vault’s Shamir secret sharing implementation relies on precomputed table lookups, making it susceptible to cache-timing attacks. An attacker with access to the host and the ability to monitor a large number of unseal operations via a side channel can significantly reduce the search space for brute-force recovery of Shamir shares.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/getsops/sops/v3 is vulnerable to Observable Timing Discrepancy in versions 3.0.0 - 3.9.4.

How to fix this

Upgrade the github.com/getsops/sops/v3 library to the patch version.