Javascript Webcrypto Short Auth Tag
Description
This detector identifies JavaScript Web Cryptography API usage with insufficient authentication tag lengths for authenticated encryption modes like GCM. Short authentication tags weaken cryptographic integrity protection and make encrypted data vulnerable to forgery attacks.
Detection Strategy
• Scans JavaScript code for Web Cryptography API method calls that configure authenticated encryption algorithms
• Identifies usage of encryption modes like AES-GCM that include authentication tag length parameters
• Triggers a vulnerability report when the authentication tag length is set below the recommended minimum secure length (typically less than 96-128 bits)
• Reports instances where tagLength property in algorithm objects is set to values that compromise cryptographic security
Vulnerable code example
async function encryptWithWeakTag(key, iv, data) {
// VULNERABLE: tagLength 64 bits is below the 96-bit security minimum
return crypto.subtle.encrypt({ name: 'AES-GCM', iv, tagLength: 64 }, key, data);
}
async function encryptWithVariableTag(key, iv, data) {
const algorithm = { name: 'AES-GCM', iv, tagLength: 32 };
// VULNERABLE: algorithm.tagLength is only 32 bits...✅ Secure code example
async function encryptWithWeakTag(key, iv, data) {
// SAFE: tagLength 128 bits provides strong authentication
return crypto.subtle.encrypt({ name: 'AES-GCM', iv, tagLength: 128 }, key, data);
}
async function encryptWithVariableTag(key, iv, data) {
const algorithm = { name: 'AES-GCM', iv, tagLength: 96 };
// SAFE: algorithm.tagLength is 96 bits (minimum recommended)...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.