Typescript Webcrypto Short Auth Tag
Description
This detector identifies WebCrypto API usage with insufficiently short authentication tags in TypeScript code. Short authentication tags in cryptographic operations can be vulnerable to brute-force attacks, compromising data integrity and authenticity guarantees.
Detection Strategy
• The detector analyzes TypeScript source code for WebCrypto API calls
• It specifically examines cryptographic operations that use authentication tags (like AES-GCM or ChaCha20-Poly1305)
• A vulnerability is reported when the authentication tag length is configured to be shorter than cryptographically secure recommendations
• The detector flags cases where tag lengths are set below industry standard minimums (typically less than 96 bits for GCM mode)
• It examines method calls and their parameters to identify insecure tag length configurations in encryption/decryption operations
Vulnerable code example
async function encryptData(key: CryptoKey, iv: Uint8Array, data: Uint8Array): Promise<ArrayBuffer> {
// VULNERABLE: tagLength 64 bits is below the 96-bit minimum for AES-GCM
return crypto.subtle.encrypt({ name: 'AES-GCM', iv, tagLength: 64 }, key, data);
}✅ Secure code example
async function encryptData(key: CryptoKey, iv: Uint8Array, data: Uint8Array): Promise<ArrayBuffer> {
// SAFE: tagLength is 128 bits (default), above the 96-bit minimum for AES-GCM
return crypto.subtle.encrypt({ name: 'AES-GCM', iv, tagLength: 128 }, key, data);
}Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.