PT-2025-34165 · Sha.Js+3 · Sha.Js+3

Chalker

·

Published

2025-08-20

·

Updated

2026-03-16

·

CVE-2025-9288

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions sha.js versions through 2.4.11
Description An improper input validation vulnerability exists in sha.js, allowing for input data manipulation. This flaw can lead to hash collisions and potentially private key extraction, threatening web applications. The vulnerability stems from missing input type checks, which permit the use of data types other than expected, resulting in undefined behavior, including hash state rewinding and the potential to transform tagged hashes into untagged hashes. Exploitation can involve manipulating the length property of input data to generate collisions or cause denial-of-service conditions.
Recommendations Update sha.js to version 2.4.12 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

AZL-66570
CVE-2025-9288
DLA-4302-1
DSA-6002-1
GHSA-95M3-7Q98-8XR5
USN-7778-1

Affected Products

Debian
Linuxmint
Ubuntu
Sha.Js