Files
oauth2-proxy/pkg
Madan Kumar e05f04ef08 fix(encryption): return an error instead of panicking on a short GCM ciphertext (#3527)
* fix(encryption): return an error instead of panicking on a short GCM ciphertext

gcmCipher.Decrypt slices ciphertext[:nonceSize] without first checking the
length, so a ciphertext shorter than the 12-byte GCM nonce triggers a
slice-bounds-out-of-range panic instead of returning an error. The sibling
cfbCipher.Decrypt already guards its IV length and returns a descriptive error;
mirror that guard for GCM so decrypting a malformed (e.g. truncated) cookie
fails cleanly. Adds a test covering both ciphers.

Signed-off-by: Madan Kumar <winklemad@outlook.com>

* docs(changelog): add entry for the GCM short-ciphertext fix

Signed-off-by: Madan Kumar <winklemad@outlook.com>

---------

Signed-off-by: Madan Kumar <winklemad@outlook.com>
2026-10-01 09:18:17 +02:00
..
2026-04-13 18:22:56 +02:00
2026-04-13 18:22:56 +02:00
2022-10-21 11:57:51 +01:00