logo

Database

Typescript Short Gcm Auth Tag

Description

This detector identifies the use of short GCM (Galois/Counter Mode) authentication tags in TypeScript cryptographic operations. Short authentication tags (typically less than 128 bits) provide weaker integrity protection and are more susceptible to forgery attacks, compromising the security of encrypted data.

Weakness:

052 - Insecure encryption algorithm

Category: Information Collection

Detection Strategy

    • Scans TypeScript code for cryptographic operations that use GCM mode encryption

    • Identifies when GCM authentication tag length is set to a value shorter than the recommended minimum (typically less than 128 bits)

    • Reports vulnerabilities when cryptographic libraries or APIs are configured with insufficient tag lengths that could allow authentication bypass or data tampering

    • Triggers on method calls, configuration objects, or parameter values that specify weak GCM tag sizes in encryption operations

Vulnerable code example

import * as crypto from 'crypto';

function encryptWithWeakAuthTag(key: Buffer, data: Buffer): Buffer {
  // VULNERABLE: authTagLength is 8 bytes (64 bits), below 96-bit minimum
  const cipher = crypto.createCipheriv('aes-256-gcm', key, '000000000000', {
    authTagLength: 8,
  });
  return Buffer.concat([cipher.update(data), cipher.final()]);...

✅ Secure code example

import * as crypto from 'crypto';

function encryptWithWeakAuthTag(key: Buffer, data: Buffer): Buffer {
  // SAFE: authTagLength is 12 bytes (96 bits), meeting minimum security requirement
  const cipher = crypto.createCipheriv('aes-256-gcm', key, '000000000000', {
    authTagLength: 12,
  });
  return Buffer.concat([cipher.update(data), cipher.final()]);...