{"id":"CVE-2025-9287","summary":"Missing type checks leading to hash rewind and passing on crafted data","details":"Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.","aliases":["GHSA-cpq7-6gpm-g9rc"],"modified":"2026-07-17T20:58:48.239933509Z","published":"2025-08-20T21:43:56.548Z","related":["openSUSE-SU-2025:15484-1"],"database_specific":{"cwe_ids":["CWE-20"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9287.json","cna_assigner":"harborist"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00005.html"},{"type":"WEB","url":"https://npmjs.com/cipher-base"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9287.json"},{"type":"ADVISORY","url":"https://github.com/browserify/cipher-base/security/advisories/GHSA-cpq7-6gpm-g9rc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9287"},{"type":"FIX","url":"https://github.com/browserify/cipher-base/pull/23"},{"type":"PACKAGE","url":"https://github.com/browserify/cipher-base"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/browserify/cipher-base","events":[{"introduced":"0"},{"last_affected":"bc18dc847050c34f11f7a0472ff13a76b53fedc6"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:browserify:cipher-base:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.4"}]}}],"versions":["v1.0.4","v1.0.3","v1.0.2","v1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-9287.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:N"}]}