]> dgit.raspbian.org Git - nodejs.git/commit
crypto: use timing-safe comparison in Web Cryptography HMAC
authorFilip Skokan <panva.ip@gmail.com>
Fri, 20 Feb 2026 11:32:14 +0000 (12:32 +0100)
committerBastien Roucariès <rouca@debian.org>
Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)
commitb4a8d2935012847db9dc9f0090abee6e673edcf1
tree775894c69cfdf3f4d9000c3da7e5010a63964d2e
parentf31963fe939dfc03c93c3875dcd1f3ac8f6c7da1
crypto: use timing-safe comparison in Web Cryptography HMAC

Use `CRYPTO_memcmp` instead of `memcmp` in `HMAC`
Web Cryptography algorithm implementations.

Ref: https://hackerone.com/reports/3533945
PR-URL: https://github.com/nodejs-private/node-private/pull/831
Refs: https://hackerone.com/reports/3533945
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
CVE-ID: CVE-2026-21713
origin: https://github.com/nodejs/node/commit/cfb51fa9ce1da2a8c810ec35bcc7c000f8c94fafy

Gbp-Pq: Name CVE-2026-21713.patch
src/crypto/crypto_hmac.cc