logo

CVE-2025-9288: Critical Flaw in Popular JavaScript Library Threatens Global Web Security

ID: 63b20881-252b-5c20-a1c6-20ba4d39f7e8

STIX ID: report--63b20881-252b-5c20-a1c6-20ba4d39f7e8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-08-22

Date Updated: 2026-04-22

Author: Ddos

...
...

A critical vulnerability (CVE-2025-9288, CVSS 9.1) was disclosed in the sha.js JavaScript library that fails to validate input types, enabling attackers to rewind hash state, create collisions or mismatched numeric interpretations, cause indefinite hangs (DoS), and in some scenarios recover private keys; users are advised to upgrade to sha.js v2.4.12 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.