pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos supported by Node.js

CVE Details

Basic Information

Title pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos supported by Node.js
Type cve
Published 2025-06-23T18:41:18.771Z
Last Seen

Product Information

Vendor
Product
Version 3.0.10

CVSS Information

Base Score 9.1 (CRITICAL)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A vulnerability in pbkdf2 allows signature spoofing due to improper input validation, affecting versions 3.0.10 to 3.1.2.
AI Severity Critical
Vendor GitHub browserify/pbkdf2
Product pbkdf2
Affected Version 3.0.10, 3.1.2

Affected Products

  • 3.0.10

Additional Information

CVE List
CWE List CWE-20
Bulletin Family

Description

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.

This issue affects pbkdf2: from 3.0.10 through 3.1.2.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.