ECHO-a985-43d5-9a0c

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-a985-43d5-9a0c.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-a985-43d5-9a0c
Upstream
Withdrawn
2026-10-08T16:30:05Z
Published
2026-10-08T14:59:47Z
Modified
2026-10-08T17:30:21Z
Summary
GHSA-r44j-crv5-q35m / NVD's own CPE match pins this to the single exact version percona-toolkit:3.6.0, with no version range -- the advisory is "unreviewed" and carries no upper bound, so CPE-based scanners (Trivy/Grype/Wiz) treat it as affecting every later version too. The vulnerable code (weak SHA-256-as-KDF password hashing in src/go/pt-secure-collect/encrypt.go) was replaced with a proper HKDF derivation upstream in commit 78f20304 ("Use KDF instead of hash"), first shipped in v3.7.0 and present in our v3.7.1 build. Independent of the version question, this package never builds pt-secure-collect at all -- only pt-online-schema-change (a separate Perl tool); the build step explicitly drops the manifypods->gotools coupling so Go tools are never compiled.
Details
References

Affected packages

Echo / percona-toolkit

Package

Name
percona-toolkit
Purl
pkg:deb/echo/percona-toolkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.7.1+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-a985-43d5-9a0c.json"