Javascript Short Gcm Auth Tag
Description
This vulnerability detector identifies weak cryptographic implementations in JavaScript that use GCM (Galois/Counter Mode) encryption with insufficiently short authentication tags. Short authentication tags significantly reduce the security strength of GCM mode, making it vulnerable to forgery attacks and compromising data integrity.
Detection Strategy
• The detector examines JavaScript code for GCM encryption implementations
• It specifically looks for GCM authentication tag configurations that are shorter than the recommended secure length
• The vulnerability is flagged when cryptographic operations use authentication tags below the minimum security threshold (typically less than 96 bits for GCM mode)
• Detection occurs during analysis of cryptographic library calls and encryption parameter settings in JavaScript source code
Vulnerable code example
const crypto = require('crypto');
function encryptWithWeakAuthTag(key, data) {
// VULNERABLE: authTagLength is 8 bytes, below 96-bit minimum
const cipher = crypto.createCipheriv('aes-256-gcm', key, '000000000000', {
authTagLength: 8,
});
return cipher.update(data);...✅ Secure code example
const crypto = require('crypto');
function encryptWithStrongAuthTag(key, data) {
// SECURE: authTagLength is 12 bytes, meeting 96-bit minimum for AES-GCM
const cipher = crypto.createCipheriv('aes-256-gcm', key, '000000000000', {
authTagLength: 12,
});
return Buffer.concat([cipher.update(data), cipher.final()]);...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.