{"id":"GHSA-gxhx-2686-5h9g","summary":"slack-go `SecretsVerifier` accepts empty signing secret without precondition","details":"`SecretsVerifier` in slack-go/slack before v0.23.1 accepts an empty signing secret without error. If an application is misconfigured (e.g., an unset or empty `SLACK_SIGNING_SECRET`), `NewSecretsVerifier` builds an HMAC-SHA256 keyed with an empty string, allowing an unauthenticated attacker to forge a valid `X-Slack-Signature` and bypass Slack request authentication. Fixed in v0.23.1, which rejects empty secrets with `ErrInvalidConfiguration`. This is patched in version 0.23.1.","aliases":["GO-2026-5410"],"modified":"2026-09-10T03:50:47.019550374Z","published":"2026-05-14T20:52:55Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-14T20:52:55Z","nvd_published_at":null,"cwe_ids":["CWE-1391","CWE-287","CWE-326"]},"references":[{"type":"WEB","url":"https://github.com/slack-go/slack/security/advisories/GHSA-gxhx-2686-5h9g"},{"type":"WEB","url":"https://github.com/slack-go/slack/commit/34ad5c052e446f58505ae8d81a2a72821de107cc"},{"type":"PACKAGE","url":"https://github.com/slack-go/slack"},{"type":"WEB","url":"https://github.com/slack-go/slack/releases/tag/v0.23.1"}],"affected":[{"package":{"name":"github.com/slack-go/slack","ecosystem":"Go","purl":"pkg:golang/github.com/slack-go/slack"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.23.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-gxhx-2686-5h9g/GHSA-gxhx-2686-5h9g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U"}]}