Threat Advisory

CryptoJS Flaw Lets Attackers Enumerate Reduced Output Space

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting crypto-js versions is not a cryptographically secure random number generator, CVE-2026-71851 with a CVSS score of 9.0, exists in crypto-js due to insufficient entropy in cryptographic secret generation via a vulnerable dependency chain. The issue affects applications that use the vulnerable function to generate security-sensitive values, such as BIP39 recovery phrases, and can be exploited by an attacker who can enumerate the reduced output space and recover these values. This flaw type is related to CWE-331, CWE-334, and CWE-338. The attack vector is network-based (AV:N), with high attack complexity (AC:H) and no user interaction required (UI:N). The business impact is significant, as previously generated secrets may remain exploitable indefinitely, future deposits to affected addresses may be stolen, and assets may remain exposed across networks or derivation paths that have not yet shown suspicious activity. Affected versions of crypto-js prior to 4.0.0 are vulnerable.

RECOMMENDATION:

We recommend you to update crypto-js to version 4.0.0.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical vulnerability affecting crypto-js versions is not a cryptographically secure random number generator, CVE-2026-71851 with a CVSS score of 9.0, exists in crypto-js due to insufficient entropy in cryptographic secret generation via a vulnerable dependency chain. The issue affects applications that use the vulnerable function to generate security-sensitive values, such as BIP39 recovery phrases, and can be exploited by an attacker who can enumerate the reduced output space and recover these values. This flaw type is related to CWE-331, CWE-334, and CWE-338. The attack vector is network-based (AV:N), with high attack complexity (AC:H) and no user interaction required (UI:N). The business impact is significant, as previously generated secrets may remain exploitable indefinitely, future deposits to affected addresses may be stolen, and assets may remain exposed across networks or derivation paths that have not yet shown suspicious activity. Affected versions of crypto-js prior to 4.0.0 are vulnerable.

RECOMMENDATION:

We recommend you to update crypto-js to version 4.0.0.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu