Executive brief
sha.js is a cryptographic hashing library used by applications to compute SHA-256 and other hash functions. Missing input validation allows attackers to pass malformed objects that can rewind the hash state, forge hash collisions, or extract private keys from downstream cryptographic systems. This can compromise the integrity of digital signatures and authentication mechanisms.
Technical details
The vulnerability is an improper input validation (CWE-20) in sha.js's update() method. The library fails to validate that input is a well-formed Buffer or string, allowing arbitrary objects with synthetic length properties (e.g., {length: -x} or {length: '1e99'}) to be accepted. This permits attackers to rewind hash state, generate hash collisions for different data, or cause denial of service. Network-reachable: an attacker can craft and send malicious objects over the network in serialized form (e.g., JSON). No authentication required. The fix is available in version 2.4.12; all prior versions are vulnerable.
Affected products
- browserify sha.js <=2.4.11
Timeline
- 2025-08-21: disclosed: GHSA-95m3-7q98-8xr5 published
- 2025-08-21: patched: Fix released in version 2.4.12