logo

Database

Python Short Gcm Auth Tag

Description

This vulnerability detector identifies when cryptographic GCM (Galois/Counter Mode) encryption uses authentication tags that are too short, weakening the security of authenticated encryption. Short authentication tags make it easier for attackers to forge encrypted messages or bypass integrity checks.

Weakness:

052 - Insecure encryption algorithm

Category: Information Collection

Detection Strategy

    • The code imports a cryptography library (specifically checking for library prefixes)

    • A function call is made to one of the predefined Python encryption methods

    • The encryption method construction uses GCM mode with an authentication tag length that is considered too short for secure cryptographic operations

    • The detector specifically looks for calls that construct GCM encryption with insufficient tag length parameters

Vulnerable code example

from Crypto.Cipher import AES

def encrypt_with_short_tag(key, data):
    nonce = b"\x00" * 12
    # VULNERABLE: mac_len=8 is below the 12-byte minimum for secure authentication
    cipher = AES.new(key, AES.MODE_GCM, nonce=nonce, mac_len=8)
    return cipher.encrypt_and_digest(data)

✅ Secure code example

from Crypto.Cipher import AES

def encrypt_with_short_tag(key, data):
    nonce = b"\x00" * 12
    # SAFE: no mac_len parameter uses secure 16-byte default
    cipher = AES.new(key, AES.MODE_GCM, nonce=nonce)
    return cipher.encrypt_and_digest(data)