Bug 2389932 (CVE-2025-9287)

Summary: CVE-2025-9287 cipher-base: Cipher-base hash manipulation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, alcohan, anjoseph, bdettelb, bkabrda, caswilli, chfoley, dhanak, doconnor, drosa, dsimansk, eric.wittmann, gmalinko, gotiwari, gparvin, ibek, janstey, jcantril, jchui, jhe, jkoehler, jprabhak, jrokos, jscholz, jwendell, kaycoth, kingland, ktsao, kverlaen, lball, lchilton, lphiri, matzew, mnovotny, mvyas, nboldt, ngough, nipatil, njean, owatkins, pahickey, pantinor, pdelbell, pjindal, psrna, rcernich, rhaigner, rkubis, rojacob, rstepani, sausingh, sdawley, sfeifer, swoodman, teagle, veshanka, wtam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
An improper input validation vulnerability was found in the cipher-base npm package. Missing input type checks in the polyfill of the Node.js `createHash` function result in invalid value calculations, hanging and rewinding the hash state, including turning a tagged hash into an untagged hash, for malicious JSON-stringifyable inputs.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2389960, 2389962, 2389965, 2389961, 2389963, 2389964, 2389966, 2389967, 2389968, 2389969    
Bug Blocks:    

Description OSIDB Bzimport 2025-08-20 22:01:17 UTC
Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

Comment 2 errata-xmlrpc 2025-10-18 03:50:41 UTC
This issue has been addressed in the following products:

  multicluster engine for Kubernetes 2.7 for RHEL 8
  multicluster engine for Kubernetes 2.7 for RHEL 9

Via RHSA-2025:18278 https://access.redhat.com/errata/RHSA-2025:18278

Comment 3 errata-xmlrpc 2025-10-21 03:15:06 UTC
This issue has been addressed in the following products:

  Red Hat Advanced Cluster Management for Kubernetes 2.12 for RHEL 9

Via RHSA-2025:18744 https://access.redhat.com/errata/RHSA-2025:18744