Contentstack - Azure EU - Webhook Signature Validation Issue

Incident Report for Contentstack

Resolved

A standard security upgrade to Node.js 24 with OpenSSL 3 was deployed as part of our security hardening efforts. The upgrade introduced stricter RSA-PSS signature validation per RFC 8017 standards, changing the default salt length from a previously lenient range (32-222) to strictly enforcing 32 for SHA-256. This impacted webhook functionality for configurations using RSA-based certificates with salt lengths greater than 32. Upon identifying the impact, the update was promptly reverted to restore normal operations.
Posted Jan 22, 2026 - 23:30 MST