GHSA-4w7r-3222-8h6v · Severity: medium · Ecosystem: go — Tillitis TKey Client has an Error in Protocol Implementation
Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored, producing the same Compound Device Identifier (CDI)—and thus the same key material—as if no USS is provided. This happens because a buffer index error overwrites the USS-enabled boolean with the first byte of the USS digest, so any USS whose hash starts with 0x00 is effectively discarded. This issue has been fixed in version 1.3.0. Users unable to upgrade immediately should switch to a USS whose hash does not begin with a zero byte.
Conclusion & alert: CVE-2026-32953 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.25%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.02% | 0.25% | +0.23% |
| 2 | 2026-03-20 | — | 0.02% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.7 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.6 | 3.1 | MEDIUM |
|
0.9 | 3.6 | [email protected] |
GHSA-4w7r-3222-8h6v · Severity: medium · Ecosystem: go — Tillitis TKey Client has an Error in Protocol Implementation
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-32953 not yet assigned priority: Debian including 1 source packages (golang-github-tillitis-tkeyclient), 3 status rows across 3 suites (forky, sid, trixie): resolved 2, open 1. | https://security-tracker.debian.org/tracker/CVE-2026-32953 |
ubuntu
|
medium | CVE-2026-32953 medium priority: Ubuntu including 1 source packages (golang-github-tillitis-tkeyclient), 4 status rows across 4 suites (jammy, noble, questing, upstream): DNE 2, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2026-32953 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tillitis | tkey_client | < 1.3.0 | cpe:2.3:a:tillitis:tkey_client:*:*:*:*:*:go:*:* |