Vulnerability library
Security checkNovember 03, 2025

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmcipher-base

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

This affects e.g. create-hash (and crypto-browserify), so I’ll describe the issue against that package Also affects create-hmac and other packages

Node.js createHash works only on strings or instances of Buffer, TypedArray, or DataView.

Missing input type checks (in npm create-hash polyfill of Node.

Recommendation

Update the cipher-base package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 1.0.4
  • Patched version(s): 1.0.5

References

Could your website be exposed too?

SmartScanner can check your website for cipher-base is missing type checks, leading to hash rewind and passing on crafted data and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 03, 2025