From d15c14ec6a8e2fca87c56c460db54f55b60d0fcb Mon Sep 17 00:00:00 2001 From: Alessandro Ros Date: Sun, 19 Jul 2026 09:46:34 +0200 Subject: [PATCH] avoid potential timing attack when validating SHA256 credentials (#5961) The == operator is vulnerable to timing attacks as it short-circuits on a mismatch. Use ConstantTimeCompare to avoid this vector. Co-authored-by: Tristan Matthews --- internal/conf/credential.go | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/internal/conf/credential.go b/internal/conf/credential.go index 94f704c5..e7779ecc 100644 --- a/internal/conf/credential.go +++ b/internal/conf/credential.go @@ -2,6 +2,7 @@ package conf import ( "crypto/sha256" + "crypto/subtle" "encoding/base64" "fmt" "regexp" @@ -62,7 +63,7 @@ func (d Credential) IsHashed() bool { // Check returns true if the given value matches the credential. func (d Credential) Check(guess string) bool { if d.IsSha256() { - return string(d)[len("sha256:"):] == sha256Base64(guess) + return subtle.ConstantTimeCompare([]byte(string(d)[len("sha256:"):]), []byte(sha256Base64(guess))) == 1 } if d.IsArgon2() { @@ -73,7 +74,7 @@ func (d Credential) Check(guess string) bool { } if d != "" { - return string(d) == guess + return subtle.ConstantTimeCompare([]byte(string(d)), []byte(guess)) == 1 } return true