CVE-2025-9288Improper Input Validation in Node-sha.js

Severity
9.1CRITICALNVD
EPSS
0.0%
top 86.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateSep 25

Description

Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:N

Affected Packages6 packages

npmbrowserify/sha.js< 2.4.12
debiandebian/node-sha.js< node-sha.js 2.4.11+~2.4.0-2+deb12u1 (bookworm)
NVDbrowserify/sha.js2.4.11

Patches

🔴Vulnerability Details

3
GHSA
sha.js is missing type checks leading to hash rewind and passing on crafted data2025-08-21
OSV
sha.js is missing type checks leading to hash rewind and passing on crafted data2025-08-21
OSV
CVE-2025-9288: Improper Input Validation vulnerability in sha2025-08-20

📋Vendor Advisories

4
Ubuntu
sha.js vulnerability2025-09-25
Red Hat
sha.js: Missing type checks leading to hash rewind and passing on crafted data2025-08-20
Microsoft
Missing type checks leading to hash rewind and passing on crafted data2025-08-12
Debian
CVE-2025-9288: node-sha.js - Improper Input Validation vulnerability in sha.js allows Input Data Manipulation...2025