Skip to content

Bug: createFastHash errors in FIPS environments #37676

Description

@MasterOdin

When running a react app within a FIPS enabled environment, anything that relies on createFastHash (such as useActionState in certain cases) will cause an error. This is because it relies on using MD5 for its hashing algorithm which is explicitly disallowed in FIPS:

const hash = createHash('md5');

The request would be to move to something that is FIPS compliant instead (e.g. sha256). A prior ticket was raised about this (#31748) with implementation PR (#31910), though was closed at the time.

A potential alternative approach if it was desired to use MD5 in majority of cases could be to do something like:

import {createHash, getFips} from 'crypto';

export function createFastHash(input: string): string | number {
  const hash = createHash(getFips() ? 'sha256' : 'md5');
  hash.update(input);
  return hash.digest('hex');
}

React version: 19.2.4

Steps To Reproduce

  1. On a FIPS enabled system, try to use createFastHash (via a hook like useActionState), see error.

Link to code example:

app/actions.js

'use server';

export async function submit(previousState, formData) {
  return `Hello, ${formData.get('name')}`;
}

app/page.js

'use client';

import { useActionState } from 'react';
import { submit } from './actions';

export default function Page() {
  const [state, formAction] = useActionState(submit, '');

  return (
    <form action={formAction}>
      <input name="name" defaultValue="World" />
      <button type="submit">Submit</button>
      <p>{state}</p>
    </form>
  );
}

If crypto.getFips() returns 1, then the above will fail.

The current behavior

Uncaught Error: error:0308010C:digital envelope routines::unsupported
    at new Hash (node:internal/crypto/hash:112:19)
    at createHash (node:crypto:146:10) {
  opensslErrorStack: [
    'error:03000086:digital envelope routines::initialization error',
    'error:0308010C:digital envelope routines::unsupported'
  ],
  library: 'digital envelope routines',
  reason: 'unsupported',
  code: 'ERR_OSSL_EVP_UNSUPPORTED'
}

The expected behavior

It doesn't error.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Status: UnconfirmedA potential issue that we haven't yet confirmed as a bug

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions