CVE-2025-9288: Critical Flaw in Popular JavaScript Library Threatens Global Web Security
ID: 63b20881-252b-5c20-a1c6-20ba4d39f7e8
STIX ID: report--63b20881-252b-5c20-a1c6-20ba4d39f7e8
Feed Name: securityonline.info
Threat Score
A critical vulnerability (CVE-2025-9288, CVSS 9.1) was disclosed in the sha.js JavaScript library that fails to validate input types, enabling attackers to rewind hash state, create collisions or mismatched numeric interpretations, cause indefinite hangs (DoS), and in some scenarios recover private keys; users are advised to upgrade to sha.js v2.4.12 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
