Input validation error in sha.js - CVE-2025-9288

 

Input validation error in sha.js - CVE-2025-9288

Published: September 26, 2025


Vulnerability identifier: #VU116130
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-9288
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to a missing type check when handling untrusted input that can lead to calculation of invalid values or rewinding the hash state. A remote attacker can pass specially crafted data to the application and bypass implemented security restrictions. 


Affected software

sha.js
Debian Linux
Ubuntu
Astronomer with IBM
watsonx Orchestrate Developer Edition
watsonx Code Assistant IDE Extensions
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
IBM Cloud Pak for Security
Crowd Data Center
Red Hat Advanced Cluster Management for Kubernetes
Jira Software Data Center
Jira Service Management Server
Jira Service Management Data Center
OpenShift Pipelines
Crowd Server
IBM Edge Application Manager
Jira Software Server
QRadar Suite
IBM Security QRadar Analyst Workflow
Splunk Security Orchestration, Automation and Response (SOAR)
node-sha.js (Ubuntu package)
node-sha.js (Debian package)
Multicluster Engine for Kubernetes

How to mitigate CVE-2025-9288

Install updates from vendor's website.

sha.js - update to 2.4.12
Astronomer with IBM - update to 1.1.0
watsonx Orchestrate Developer Edition - update to 1.13.0
watsonx Code Assistant IDE Extensions - update to 1.9.3
IBM Cloud Pak for Security - update to 1.11.9.0
Crowd Server - update to 7.1.2
Crowd Data Center - update to 7.1.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.11.9, 2.12.5, 2.13.5
Jira Software Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Software Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Server - addressed in versions 10.3.16, 11.2.1, 11.3.0
Jira Service Management Data Center - addressed in versions 10.3.16, 11.2.1, 11.3.0
QRadar Suite - update to 1.11.9.0
OpenShift Pipelines - update to 1.19.4
node-sha.js (Ubuntu package) - addressed in versions 2.4.9-1ubuntu0.1~esm1, 2.4.11+~2.4.0-1ubuntu0.1, 2.4.11+~2.4.0-2+deb13u1build0.24.04.1, 2.4.11+~2.4.0-2+deb13u1build0.25.04.1, 2.4.11-2ubuntu0.1~esm1
node-sha.js (Debian package) - addressed in versions 2.4.11+~2.4.0-2+deb12u1, 2.4.11+~2.4.0-2+deb13u1
Multicluster Engine for Kubernetes - addressed in versions 2.6, 2.7.6
IBM Security QRadar Analyst Workflow - update to 3.0.1
watsonx Assistant Cartridge - update to 5.3.0
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.3.0
Splunk Security Orchestration, Automation and Response (SOAR) - update to 7.1.0

External References

Related Security Bulletins