github.com/protonmail/go-crypto is vulnerable to Improper Input Validation
58
Medium Risk
Affected versions of this package do not properly validate an user-controlled elliptic curve point during encapsulation and may panic when malformed input is provided instead of safely rejecting it. This can allow denial of service and may also expose the key agreement flow to invalid public point abuse if the untrusted point is used for shared secret derivation without strict validation. An attacker could exploit this by sending a crafted malicious point to trigger a panic and crash the application, or potentially manipulate cryptographic operations by supplying an invalid point designed to interfere with secret generation.
You are affected if you are using a version that falls within the vulnerable range.
github.com/protonmail/go-crypto is vulnerable to Improper Input Validation in versions 1.0.0 - 1.4.0.
Upgrade the github.com/protonmail/go-crypto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant