PT-2025-34165 · Sha.Js+3 · Sha.Js+3
Chalker
·
Published
2025-08-20
·
Updated
2026-03-16
·
CVE-2025-9288
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
sha.js versions through 2.4.11
Description
An improper input validation vulnerability exists in sha.js, allowing for input data manipulation. This flaw can lead to hash collisions and potentially private key extraction, threatening web applications. The vulnerability stems from missing input type checks, which permit the use of data types other than expected, resulting in undefined behavior, including hash state rewinding and the potential to transform tagged hashes into untagged hashes. Exploitation can involve manipulating the length property of input data to generate collisions or cause denial-of-service conditions.
Recommendations
Update sha.js to version 2.4.12 or later.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Sha.Js