CVE-2026-32953 identifies a critical buffer index error in the Tillitis TKey Client package (tkeyclient Go module) versions 1.2.0 and below. This flaw causes 1 in 256 User Supplied Secrets (USS) to be silently ignored if its hash begins with 0x00, resulting in the generation of identical key material as if no USS was provided. Rated Medium with a CVSS score of 4.7, exploitation requires physical access (AV:P) but has low complexity (AC:L), potentially compromising security confidentiality, integrity, and availability (SC:H, SI:H, SA:H) by undermining the uniqueness of cryptographic keys. The vulnerability is fixed in version 1.3.0, with a workaround suggesting users switch to a USS whose hash does not begin with a zero byte. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:tillitis:tkey_client:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.