Vulnerability GHSA-h7cp-r72f-jxh6

Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
1 year ago
June 23, 2025 at 10:41 PM UTC
pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos
3.0.10 - 3.1.2
3.0.10 - 3.1.2

Summary

pbkdf2 returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos

Details

Summary

This affects both:

  1. Unsupported algos (e.g. sha3-256 / sha3-512 / sha512-256)
  2. Supported but non-normalized algos (e.g. Sha256 / Sha512 / SHA1 / sha-1 / sha-256 / sha-512)

All of those work correctly in Node.js, but this polyfill silently returns highly predictable ouput

Under Node.js (only with pbkdf2/browser import, unlikely) / Bun (pbkdf2 top-level import is affected), the memory is not zero-filled but is uninitialized, as Buffer.allocUnsafe is used

Under browsers, it just returns zero-filled buffers (Which is also critical, those are completely unacceptable as kdf output and ruin security)

Were you affected?

The full list of arguments that were not affected were literal:

  • 'md5'
  • 'sha1'
  • 'sha224'
  • 'sha256'
  • 'sha384'
  • 'sha512'
  • 'rmd160'
  • 'ripemd160'

Any other arguments, e.g. representation variations of the above ones like 'SHA-1'/'sha-256'/'SHA512' or different algos like 'sha3-512'/'blake2b512', while supported on Node.js crypto module, returned predictable output on pbkdf2 (or crypto browser/bundlers polyfill)

Impacted packages

Timeline

Published
1 year ago
June 23, 2025 at 10:41 PM UTC
Fixed (3.1.3)
1 year ago
June 20, 2025 at 08:37 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC