VDB
Sign up
—

RUSTSEC-2024-0010

Improper comparison of different-length signatures

Details

The `Webhook::verify` function incorrectly compared signatures of different lengths - the two signatures would only be compared up to the length of the shorter signature. This allowed an attacker to pass in `v1,` as the signature, which would always pass verification.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/svix
Introduced in: 0.0.0-0Fixed in: 1.17.0

Upgrade svix to 1.17.0 or newer (ecosystem crates.io).

References