Java Short Gcm Auth Tag
Description
This detector identifies Java applications using GCM (Galois/Counter Mode) encryption with insufficiently short authentication tags. Short GCM authentication tags (typically less than 96 bits) are cryptographically weak and can be vulnerable to forgery attacks, compromising the integrity and authenticity of encrypted data.
Detection Strategy
• The code must import javax.crypto.spec library or related cryptographic packages
• The analyzer identifies calls to encryption initialization methods (like Cipher.init())
• The method examines the GCMParameterSpec argument passed to the encryption initialization
• A vulnerability is reported when the GCM authentication tag length is determined to be too short (less than the recommended minimum of 96 bits)
• The detection focuses on parameter specifications that define weak tag lengths in GCM mode encryption
Vulnerable code example
import java.security.SecureRandom;
import javax.crypto.Cipher;
import javax.crypto.spec.GCMParameterSpec;
import javax.crypto.spec.SecretKeySpec;
class WeakGCMAuth {
static byte[] encrypt(SecretKeySpec keySpec, byte[] data) throws Exception {
byte[] iv = new byte[12];...✅ Secure code example
import java.security.SecureRandom;
import javax.crypto.Cipher;
import javax.crypto.spec.GCMParameterSpec;
import javax.crypto.spec.SecretKeySpec;
class WeakGCMAuth {
static byte[] encrypt(SecretKeySpec keySpec, byte[] data) throws Exception {
byte[] iv = new byte[12];...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.