Repository navigation
Additional validation of tag length in AES GCM decryption #17523
Description
Activity
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.
on Dec 7, 2017 but configurable by users who have a good reason to allow shorter tags
Can you post a concrete API proposal?
@bnoordhuis Updated the description to include an API proposal.
cc @nodejs/crypto - your input please.
I'll try to clarify your proposal just to make sure I did not miss anything:
crypto.createDecipherivshould accept an optionminimumTagByteswhose value must be a valid authentication tag length, otherwise the function throws. The option defaults to 128 bits (16 bytes).decipher.setAuthTag(tag)should throw if the length of thetagis either invalid (not one of 128, 120, 112, 104, 96, 64, 32 bits) or smaller thanminimumTagBytes.
Even though
minimumTagBytesdoes not necessarily need to be implemented in Node.js core, the security implications of accidentally accepting small tag lengths justify it in my opinion.If this is correct, I can probably put together a PR on the weekend. There are three relevant changes here:
setAuthTag(tag)throws if the tag length is invalid. I would go with semver-minor or maybe even semver-patch here.crypto.createDecipheraccepts aminimumTagBytesoption and causessetAuthTagto throw when the tag is too short. This would be semver-minor.crypto.createDecipheruses 128 bits as the default value forminimumTagBytes. This will cause existing applications to fail if they depend on the old behavior, so this would be a semver-major change. We could add a runtime deprecation for usingcreateCipherwith tags shorter than 128 bits.
@tniessen That’s exactly what I meant and those semver assessments seem correct. In my opinion semver-patch would make sense for the first change: I was pretty surprised to discover
decipher.setAuthTag(validTag.slice(0, 1))let me decrypt without complaint!Oh except I’ve only been talking about
crypto.createDecipheriv. I suppose it should also apply tocrypto.createDeciphereven though people shouldn’t really be using it with GCM.I suppose it should also apply to
crypto.createDeciphereven though people shouldn’t really be using it with GCM.Ref #13941
setAuthTag(tag) throws if the tag length is invalid. I would go with semver-minor or maybe even semver-patch here.
Right now, any 1 <= tag length <= 16 is accepted (because openssl accepts it) and there might therefore be code in the wild that uses odd sizes.
Throwing an exception must be semver-major for that reason but logging a warning for e.g. lengths < 8 can be semver-patch.
crypto.createDecipher accepts a minimumTagBytes option and causes setAuthTag to throw when the tag is too short
Call me a pessimist but I predict most usage is going to look like this...
var tag = getTagFromSomewhere(); var dec = crypto.createDecipheriv(algo, key, iv, { minimumTagBytes: tag.length }); dec.setAuthTag(tag);
More boilerplate, zero extra security.
We'll probably get better results from improving the documentation and adding big fat warnings that people must check that the tag is what they expect it to be.
@bnoordhuis If we decide to set the default value of
minimumTagBytesto 128 bits as a semver-major change, it might increase security considering that people will need to manually setminimumTagBytesto allow shorter tags, and at that point they are hopefully looking at our docs.Reacted by Will Clark, Ștefan Rusu and Joran Dirk Greef- added a commit that references this issue
on Dec 9, 2017 - added a commit that references this issue
on Dec 15, 2017 - added 3 commits that reference this issue
on Dec 22, 2017 48 remaining items
- added a commit that references this issue
on May 14, 2018 - added a commit that references this issue
on Dec 18, 2025 - added a commit that references this issue
on Dec 18, 2025 - added a commit that references this issue
on Dec 20, 2025 - added 2 commits that reference this issue
on Jan 9, 2026 - added a commit that references this issue
on Jan 13, 2026 - added a commit that references this issue
on Jan 19, 2026 - added a commit that references this issue
on Jul 27, 2026
I notice here that validation of tag length is planned when using authenticated decryption:
node/src/node_crypto.cc
Line 3713 in 50ec9bf
I'm assuming this comment addresses the fact that the current implementation doesn't check whether the provided tag conforms to the valid tag lengths for GCM: 128, 120, 112, 104, or 96 (or 64 or 32 for certain applications) according to this document).
Even with such validation however, if no default minimum tag length is enforced, there is a lot of scope for insecure use of authenticated encryption, where developers authenticate decryption in a manner that accepts shorter tags than necessary (e.g. 32 bits when they only ever intend to use 128-bit tags).
A solution would be to validate tag length against not only the list of valid lengths according to the specification, but also a minimum length (128 bits by default, but configurable by users who have a good reason to allow shorter tags).
For example:
Caveats with the above proposal:
minimumTagBytesvalue or when calling.final()) or how to word error messages.