PT-2026-25989 · Tillitis · Tillitis Tkey Client+1
Dehanj
·
Published
2026-01-01
·
Updated
2026-03-27
·
CVE-2026-32953
CVSS v4.0
4.7
Medium
| Vector | AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Tillitis TKey Client versions 1.2.0 and below
Description
The Tillitis TKey Client package, a Go package for a TKey client, contains a flaw in the tkeyclient Go module. Approximately 1 out of every 256 User Supplied Secrets (USS) are silently ignored, resulting in the same Compound Device Identifier (CDI) and key material as if no USS was provided. This occurs due to a buffer index error that overwrites the USS-enabled boolean with the first byte of the USS digest, effectively discarding any USS whose hash begins with 0x00. The
LoadApp() function calls the internal loadApp() function, which contains the vulnerable code. The issue affects all client applications utilizing the tkeyclient Go module.
Recommendations
Upgrade to version 1.3.0.
For users unable to upgrade immediately, switch to a USS whose hash does not begin with a zero byte.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tillitis Tkey Client
Tkeyclient