slack-go `SecretsVerifier` accepts empty signing secret without precondition
The slack-go library before version 0.23.1 contains a vulnerability in the SecretsVerifier component where it accepts an empty signing secret without error. This allows an attacker to forge a valid X-Slack-Signature header and bypass Slack request authentication if the application is misconfigured with an empty or unset SLACK_SIGNING_SECRET. The issue is fixed in version 0.23.1, which rejects empty secrets with an explicit error.
AI Analysis
Technical Summary
In slack-go/slack versions prior to 0.23.1, the SecretsVerifier component does not validate that the signing secret is non-empty. When the signing secret is empty or unset, NewSecretsVerifier creates an HMAC-SHA256 keyed with an empty string, enabling an unauthenticated attacker to forge valid Slack request signatures and bypass authentication. This vulnerability is addressed in version 0.23.1 by rejecting empty secrets and returning ErrInvalidConfiguration.
Potential Impact
If an application using slack-go is misconfigured with an empty or unset SLACK_SIGNING_SECRET, an attacker can bypass Slack request authentication by forging the X-Slack-Signature header. This could allow unauthorized requests to be accepted as legitimate, potentially leading to unauthorized actions or data exposure within the affected application.
Mitigation Recommendations
Upgrade to slack-go version 0.23.1 or later, where the vulnerability is fixed by rejecting empty signing secrets. Ensure that the SLACK_SIGNING_SECRET environment variable or configuration is properly set and not empty to prevent this issue.
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Description
The slack-go library before version 0.23.1 contains a vulnerability in the SecretsVerifier component where it accepts an empty signing secret without error. This allows an attacker to forge a valid X-Slack-Signature header and bypass Slack request authentication if the application is misconfigured with an empty or unset SLACK_SIGNING_SECRET. The issue is fixed in version 0.23.1, which rejects empty secrets with an explicit error.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In slack-go/slack versions prior to 0.23.1, the SecretsVerifier component does not validate that the signing secret is non-empty. When the signing secret is empty or unset, NewSecretsVerifier creates an HMAC-SHA256 keyed with an empty string, enabling an unauthenticated attacker to forge valid Slack request signatures and bypass authentication. This vulnerability is addressed in version 0.23.1 by rejecting empty secrets and returning ErrInvalidConfiguration.
Potential Impact
If an application using slack-go is misconfigured with an empty or unset SLACK_SIGNING_SECRET, an attacker can bypass Slack request authentication by forging the X-Slack-Signature header. This could allow unauthorized requests to be accepted as legitimate, potentially leading to unauthorized actions or data exposure within the affected application.
Mitigation Recommendations
Upgrade to slack-go version 0.23.1 or later, where the vulnerability is fixed by rejecting empty signing secrets. Ensure that the SLACK_SIGNING_SECRET environment variable or configuration is properly set and not empty to prevent this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gxhx-2686-5h9g
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a42ed4c27e9c79719935e0e
Added to database: 06/29/2026, 22:10:20 UTC
Last enriched: 06/29/2026, 22:28:03 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 15
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.