{"id":"GHSA-w277-wpqf-rcfv","summary":"Duplicate Advisory: Svix vulnerable to improper comparison of different-length signatures","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-747x-5m58-mq97. This link is maintained to preserve external references.\n\n## Original Description\nThe `Webhook::verify` function incorrectly compared signatures of different lengths - the two signatures would only be compared up to the length of the shorter signature. This allowed an attacker to pass in `v1,` as the signature, which would always pass verification.","aliases":["CVE-2024-21491","GHSA-747x-5m58-mq97","RUSTSEC-2024-0010"],"modified":"2026-02-03T03:08:16.513003Z","published":"2024-02-06T20:30:14Z","withdrawn":"2026-01-23T22:35:18Z","database_specific":{"github_reviewed_at":"2024-02-06T20:30:14Z","nvd_published_at":null,"cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/svix/svix-webhooks/pull/1190"},{"type":"WEB","url":"https://github.com/svix/svix-webhooks/commit/958821bd3b956d1436af65f70a0964d4ffb7daf6"},{"type":"PACKAGE","url":"https://github.com/svix/svix-webhooks"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2024-0010.html"}],"affected":[{"package":{"name":"svix","ecosystem":"crates.io","purl":"pkg:cargo/svix"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.17.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-w277-wpqf-rcfv/GHSA-w277-wpqf-rcfv.json"}}],"schema_version":"1.9.0"}