CVE-2025-9288CRITICALCVSS 9.1fixed in node-sha.js 2.4.11+~2.4.0-2+deb12u1 (bookworm)2025
CVE-2025-9288 [CRITICAL] CVE-2025-9288: node-sha.js - Improper Input Validation vulnerability in sha.js allows Input Data Manipulation...
Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.
Scope: local
bookworm: resolved (fixed in 2.4.11+~2.4.0-2+deb12u1)
bullseye: resolved (fixed in 2.4.11-2+deb11u1)
forky: resolved (fixed in 2.4.12+~3.0.5-1)
sid: resolved (fixed in 2.4.12+~3.0.5-1)
trixie: resolved (fixed in 2.4.11+~2.4.0
debian