Input validation error in cipher-base - CVE-2025-9287
Published: September 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to manipulate data or perform a denial of service attack.
The vulnerability exists due to a missing type check of untrusted input. A remote attacker can manipulate data representation within the application, which can lead to denial of service conditions or various calculation errors when handling private keys or hashes.
Affected software
Debian Linux
Ubuntu
Crowd Server
Crowd Data Center
IBM Cloud Pak for Security
Red Hat Advanced Cluster Management for Kubernetes
Jira Service Management Server
Jira Software Data Center
Jira Service Management Data Center
OpenShift Pipelines
Jira Software Server
node-cipher-base (Ubuntu package)
node-cipher-base (Debian package)
QRadar Suite
Splunk Security Orchestration, Automation and Response (SOAR)
Multicluster Engine for Kubernetes
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
How to mitigate CVE-2025-9287
Crowd Server - update to 7.1.2
Crowd Data Center - update to 7.1.2
IBM Cloud Pak for Security - update to 1.11.9.0
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.12.5, 2.13.5
Jira Software Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Software Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
node-cipher-base (Ubuntu package) - addressed in versions 1.0.4-1ubuntu0.1~esm2, 1.0.4-4ubuntu0.1~esm2, 1.0.4-6+deb13u1ubuntu0.22.04.1, 1.0.4-6+deb13u1ubuntu0.24.04.1, 1.0.4-6+deb13u1ubuntu0.25.04.1
node-cipher-base (Debian package) - addressed in versions 1.0.4-6+deb12u1, 1.0.4-6+deb13u1
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.7.6
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
watsonx Assistant Cartridge - update to 5.3.0
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
External References
Related Security Bulletins
- Improper input validation in cipher-base
- Debian update for node-cipher-base
- Ubuntu update for node-cipher-base
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Release 1.19
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for cipher-base
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Jira Service Management Data Center and Server update for cipher-base
- Jira Software Data Center and Server update for cipher-base
- Splunk SOAR update for third-party components
- Crowd Data Center and Server update for cipher-base
- Multiple vulnerabilities in IBM QRadar Suite