Critical Key Derivation Flaws in pbkdf2 Affect Millions of JavaScript Projects, PoC Available

https://securityonline.info/critical-key-derivation-flaws-in-pbkdf2-affect-millions-of-javascript-projects-poc-available/

5 points · 4 comments · view on lemmy.world

4 Comments

redsand@lemmy.dbzer0.com · 3 pts · 1y

Summary copy pasta

A critical vulnerability in the pbkdf2 library affecting versions 3.0.10 through 3.1.2. The vulnerability involves improper input validation that can cause browserifying code to silently generate zero-filled cryptographic keys instead of proper ones, particularly when used in environments different from Node.js or test settings.

So pretty bad. 8.1 out of ten for setting your crypto keys to match the US nuclear arsenal in the 80s

koper@feddit.nl · 1 pts · 1y (2 replies)

Paywalled.

kid@sh.itjust.works · 3 pts · 1y

Sorry. It was not paywalled for me when I first saw. More info from different source: https://feedly.com/cve/CVE-2025-6545

kid@sh.itjust.works · 1 pts · 1y