Junglewise Threat Intelligence

CVE-2025-9288: sha.js missing type checks in hash update leading to state rewind

CVE-2025-9288 · Severity: low · CVSS 3.1 · Published 2025-08-21

Vendors: npm.

Executive brief

sha.js is a cryptographic hashing library used by applications to compute SHA-256 and other hash functions. Missing input validation allows attackers to pass malformed objects that can rewind the hash state, forge hash collisions, or extract private keys from downstream cryptographic systems. This can compromise the integrity of digital signatures and authentication mechanisms.

Technical details

The vulnerability is an improper input validation (CWE-20) in sha.js's update() method. The library fails to validate that input is a well-formed Buffer or string, allowing arbitrary objects with synthetic length properties (e.g., {length: -x} or {length: '1e99'}) to be accepted. This permits attackers to rewind hash state, generate hash collisions for different data, or cause denial of service. Network-reachable: an attacker can craft and send malicious objects over the network in serialized form (e.g., JSON). No authentication required. The fix is available in version 2.4.12; all prior versions are vulnerable.

Affected products

  • browserify sha.js <=2.4.11

Timeline

  • 2025-08-21: disclosed: GHSA-95m3-7q98-8xr5 published
  • 2025-08-21: patched: Fix released in version 2.4.12

References