gchq/CyberChef · error · OperationError

${err}

Error message

${err}

What it means

The fallback re-throw in GOST Key Unwrap's try/catch: any crypto-gost-js error whose message does NOT contain "Invalid typed array length" is wrapped here. Covers bad hex in key/ukm/input, a KEK that isn't 256 bits, an unsupported keyWrapping scheme, or engine construction failures.

Source

Thrown at src/core/operations/GOSTKeyUnwrap.mjs:136

            length: blockLength,
            mode: "KW",
            sBox: sBoxVal,
            keyWrapping: keyWrapping
        };

        try {
            const Hex = CryptoGost.coding.Hex;
            algorithm.ukm = Hex.decode(ukm);

            const cipher = GostEngine.getGostCipher(algorithm);
            const out = Hex.encode(cipher.unwrapKey(Hex.decode(key), Hex.decode(input)));

            return outputType === "Hex" ? out : Utils.byteArrayToChars(fromHex(out));
        } catch (err) {
            if (err.toString().includes("Invalid typed array length")) {
                throw new OperationError("Incorrect input length. Must be a multiple of the block size.");
            }
            throw new OperationError(err);
        }
    }

}

export default GOSTKeyUnwrap;

View on GitHub (pinned to 4290ea7539)

Solutions

  1. Provide a 32-byte (64-hex) KEK.
  2. Decode UKM to the length the wrapping scheme expects.
  3. Ensure all hex fields contain only hex digits.
  4. Inspect the preserved `err` for the library's exact message.

Example fix

// before
key = "aabb"; // KEK too short
ukm = "zz"; // not hex
// after
key = "aabb...".padEnd(64,"0"); // 32-byte KEK
ukm = "00112233445566778899aabbccddeeff";
Defensive patterns

Strategy: try-catch

Validate before calling

if (hexKey.length !== 64) throw new Error("KEK must be 32 bytes / 64 hex chars");
if (!/^[0-9a-fA-F]*$/.test(ukm) || ukm.length % 2 !== 0) throw new Error("UKM must be valid hex");

Type guard

function isHex(s){return typeof s==="string"&&/^[0-9a-fA-F]*$/.test(s)&&s.length%2===0;}

Try / catch

try { chef.bake(input, recipe); }
catch (e) { if (/hex|key|ukm|length/i.test(e.message||"")) handleUserError(e); else throw e; }

Prevention

When it happens

Trigger: Key (KEK) not 32 bytes; UKM hex invalid or wrong length; non-hex characters in input; a keyWrapping value the library rejects; algorithm/version internal inconsistency.

Common situations: Pasting a base64 KEK into a Hex field; UKM of wrong length for the wrapping mode; interop with tooling using a non-default keyWrapping diversity type.

Related errors


AI-assisted analysis of gchq/CyberChef@4290ea7539 (2026-08-13). Data as JSON: /api/errors/12d42fb6149b2b3b. Report an issue: GitHub.