{"record":{"id":"a1c9bb2c10b7a694","repo":"gofiber/fiber","slug":"failed-to-create-gcm-mode-w","errorCode":null,"errorMessage":"failed to create GCM mode: %w","messagePattern":"failed to create GCM mode: %w","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/encryptcookie/utils.go","lineNumber":54,"sourceCode":"\t_, err := decodeKey(key)\n\treturn err\n}\n\n// EncryptCookie Encrypts a cookie value with specific encryption key\nfunc EncryptCookie(name, value, key string) (string, error) {\n\tkeyDecoded, err := decodeKey(key)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\n\tblock, err := aes.NewCipher(keyDecoded)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create AES cipher: %w\", err)\n\t}\n\n\tgcm, err := cipher.NewGCMWithRandomNonce(block)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to create GCM mode: %w\", err)\n\t}\n\n\tciphertext := gcm.Seal(nil, nil, []byte(value), []byte(name))\n\treturn base64.StdEncoding.EncodeToString(ciphertext), nil\n}\n\n// DecryptCookie Decrypts a cookie value with specific encryption key\nfunc DecryptCookie(name, value, key string) (string, error) {\n\tkeyDecoded, err := decodeKey(key)\n\tif err != nil {\n\t\treturn \"\", err\n\t}\n\n\tenc, err := base64.StdEncoding.DecodeString(value)\n\tif err != nil {\n\t\treturn \"\", fmt.Errorf(\"failed to base64-decode value: %w\", err)\n\t}\n","sourceCodeStart":36,"sourceCodeEnd":72,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/encryptcookie/utils.go#L36-L72","documentation":"Returned by EncryptCookie when cipher.NewGCMWithRandomNonce fails after the AES block cipher was created. The Go stdlib only errors here if the block size is unsupported; AES blocks are always 128-bit so this branch is effectively unreachable for valid AES keys. Because decodeKey already enforces 16/24/32-byte lengths, hitting it implies an unexpected crypto/cipher runtime state or a corrupted binary.","triggerScenarios":"Calling encryptcookie.EncryptCookie(name, value, key) with a key that passed base64+length validation but for which cipher.NewGCMWithRandomNonce(block) returns a non-nil error. In practice this never fires with stdlib AES; it would only surface if a custom/modified aes.NewCipher returned a block with a non-standard block size.","commonSituations":"Developers see this only as a defensive guard. It can appear after swapping the stdlib crypto/aes for a faulty fork, on exotic GOOS/GOARCH builds with broken crypto assembly, or when fuzzing the cipher layer. Standard deployments never encounter it.","solutions":["Confirm the error is not actually from decodeKey or aes.NewCipher (read the wrapped %w chain) — those are the real-world causes.","Ensure you are using the unmodified Go standard library crypto/aes (no vendored forks).","Regenerate the key with encryptcookie.GenerateKey(32) to rule out key-shape corruption.","If genuinely hit, file a Go stdlib issue; this branch is not actionable from application code."],"exampleFix":"// before\nkey := \"some-hardcoded-value\"\nenc, err := encryptcookie.EncryptCookie(name, value, key)\n// after\nkey := encryptcookie.GenerateKey(32) // valid base64 AES-256 key\nenc, err := encryptcookie.EncryptCookie(name, value, key)\nif err != nil {\n    return fmt.Errorf(\"encrypt cookie: %w\", err)\n}","handlingStrategy":"try-catch","validationCode":"if err := encryptcookie.KeyValidator(key); err != nil { return fmt.Errorf(\"boot: %w\", err) }","typeGuard":null,"tryCatchPattern":"enc, err := encryptcookie.EncryptCookie(name, value, key)\nif err != nil {\n    if errors.Is(err, cipher.NewGCMWithRandomNonceError) { /* unreachable in practice */ }\n    return fmt.Errorf(\"encrypt cookie: %w\", err)\n}","preventionTips":["Generate keys with encryptcookie.GenerateKey(16|24|32) at deploy time.","Validate the key once at startup via KeyValidator.","Never fork crypto/aes; rely on the Go standard library."],"tags":["crypto","aes-gcm","encryptcookie","stdlib"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}