{"id":"GHSA-gxhx-2686-5h9g","aliases":["GO-2026-5410"],"url":"https://o3.security/vulnerability/GHSA-gxhx-2686-5h9g","summary":"slack-go `SecretsVerifier` accepts empty signing secret without precondition","details":"`SecretsVerifier` in slack-go/slack before v0.23.1 accepts an empty signing secret without error. If an application is misconfigured (e.g., an unset or empty `SLACK_SIGNING_SECRET`), `NewSecretsVerifier` builds an HMAC-SHA256 keyed with an empty string, allowing an unauthenticated attacker to forge a valid `X-Slack-Signature` and bypass Slack request authentication. Fixed in v0.23.1, which rejects empty secrets with `ErrInvalidConfiguration`. This is patched in version 0.23.1.","published":"2026-05-14T20:52:55Z","modified":"2026-07-13T05:15:09.410908561Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/slack-go/slack","fixedVersion":"0.23.1"}],"fix":{"url":"https://github.com/slack-go/slack/commit/34ad5c052e446f58505ae8d81a2a72821de107cc","label":"slack-go/slack@34ad5c0"},"references":[{"type":"WEB","url":"https://github.com/slack-go/slack/security/advisories/GHSA-gxhx-2686-5h9g"},{"type":"WEB","url":"https://github.com/slack-go/slack/commit/34ad5c052e446f58505ae8d81a2a72821de107cc"},{"type":"PACKAGE","url":"https://github.com/slack-go/slack"},{"type":"WEB","url":"https://github.com/slack-go/slack/releases/tag/v0.23.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T05:15:09.410908561Z"}}