Executive brief
Arnika, a tool used for secure key management and quantum-resistant communication, is affected by three security flaws. These issues could allow an attacker to disrupt secure network tunnels, bypass certificate verification when connecting to key management services, or cause the system to use weaker encryption than intended. While these flaws do not allow direct theft of secret keys or remote control of the system, they can lead to service outages or a silent reduction in the strength of your data protection.
Technical details
Arnika <= 1.0.0 contains three distinct vulnerabilities. First, the UDP key-rotation protocol fails to validate ACK timestamps in `udpserver.go`, allowing a Man-in-the-Middle (MITM) attacker to replay stale ACKs and cause tunnel desynchronization. Second, the PQC key file handler in `repositories/pqc.go` silently accepts empty files, leading to a security downgrade where HKDF derivation relies solely on QKD keys. Third, the KMS HTTP client in `repositories/kms.go` hardcodes `InsecureSkipVerify: true`, completely bypassing TLS certificate validation. These issues require either network MITM positioning or local directory write access to exploit. A fix is available in version 1.0.1.
Affected products
- arnika-project arnika <= 1.0.0
Timeline
- 2026-05-11: disclosed
- 2026-05-15: advisory: GitHub Advisory published
- 2026-05-15: patched: Version 1.0.1 released