Input validation error in sha.js - CVE-2025-9288
Published: September 26, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to a missing type check when handling untrusted input that can lead to calculation of invalid values or rewinding the hash state. A remote attacker can pass specially crafted data to the application and bypass implemented security restrictions.
Affected software
Debian Linux
Ubuntu
Astronomer with IBM
watsonx Orchestrate Developer Edition
watsonx Code Assistant IDE Extensions
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Cloud Pak for Security
Crowd Data Center
Red Hat Advanced Cluster Management for Kubernetes
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
OpenShift Pipelines
Crowd Server
IBM Edge Application Manager
Jira Software Server
QRadar Suite
IBM Security QRadar Analyst Workflow
Splunk Security Orchestration, Automation and Response (SOAR)
node-sha.js (Ubuntu package)
node-sha.js (Debian package)
Multicluster Engine for Kubernetes
How to mitigate CVE-2025-9288
Astronomer with IBM - update to 1.1.0
watsonx Orchestrate Developer Edition - update to 1.13.0
watsonx Code Assistant IDE Extensions - update to 1.9.3
IBM Cloud Pak for Security - update to 1.11.9.0
Crowd Server - update to 7.1.2
Crowd Data Center - update to 7.1.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.12.5, 2.13.5
Jira Software Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Software Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
node-sha.js (Ubuntu package) - addressed in versions 2.4.9-1ubuntu0.1~esm1, 2.4.11+~2.4.0-1ubuntu0.1, 2.4.11+~2.4.0-2+deb13u1build0.24.04.1, 2.4.11+~2.4.0-2+deb13u1build0.25.04.1, 2.4.11-2ubuntu0.1~esm1
node-sha.js (Debian package) - addressed in versions 2.4.11+~2.4.0-2+deb12u1, 2.4.11+~2.4.0-2+deb13u1
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.7.6
IBM Security QRadar Analyst Workflow - update to 3.0.1
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0
External References
Related Security Bulletins
- Security restrictions bypass in sha.js
- Ubuntu update for node-sha.js
- Debian update for node-sha.js
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- IBM watsonx Orchestrate Developer Edition update for sha.js
- IBM watsonx Code Assistant IDE Extensions update for sha.js
- Multiple vulnerabilities in Red Hat OpenShift Pipelines Release 1.19
- Multiple vulnerabilities in Red Hat Multicluster Engine for Kubernetes
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in IBM Security QRadar Analyst Workflow for IBM QRadar SIEM
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge update for sha.js
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Jira Service Management Data Center and Server update for sha.js
- Astronomer with IBM update for sha.js
- Jira Software Data Center and Server update for sha.js
- Splunk SOAR update for third-party components
- Crowd Data Center and Server update for sha.js
- Multiple vulnerabilities in IBM QRadar Suite