{"id":"GO-2026-5052","summary":"Vulnerability in software.sslmate.com/src/go-pkcs12","details":"Users who decode PKCS#12 files from untrusted sources and rely on the password for authentication can be tricked into accepting malicious PKCS#12 files.","aliases":["GHSA-mpwr-8vm7-h73f"],"modified":"2026-06-26T13:44:19.242514716Z","published":"2026-06-22T21:24:28Z","related":["CGA-x3hw-m2cv-vww4"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5052","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/SSLMate/go-pkcs12/security/advisories/GHSA-mpwr-8vm7-h73f"},{"type":"FIX","url":"https://github.com/SSLMate/go-pkcs12/commit/03c441f6b0267f695ca02464133c0b373bf4dd55"}],"affected":[{"package":{"name":"software.sslmate.com/src/go-pkcs12","ecosystem":"Go","purl":"pkg:golang/software.sslmate.com/src/go-pkcs12"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.6.0"},{"fixed":"0.7.2"}]}],"ecosystem_specific":{"imports":[{"symbols":["Decode","DecodeChain","DecodeTrustStore","ToPEM"],"path":"software.sslmate.com/src/go-pkcs12"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5052.json"}}],"schema_version":"1.7.5"}