Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Node Pbkdf2 Can Generate Predictable Cryptographic Keys

USN-8452-1
Summary

The Node Pbkdf2 library does not properly check certain algorithm names, which could allow an attacker to generate predictable cryptographic keys. This could be used to forge digital signatures. To fix this, update the Node Pbkdf2 library to the latest version, which includes a patch for this issue.

What to do
  • Update canonical node-pbkdf2 to version 3.0.14-2ubuntu0.1~esm1.
  • Update canonical node-pbkdf2 to version 3.0.16-1ubuntu0.1~esm1.
  • Update canonical node-pbkdf2 to version 3.1.2-2ubuntu0.1~esm1.
  • Update canonical node-pbkdf2 to version 3.1.2-3ubuntu0.1~esm1.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:18.04:LTS canonical node-pbkdf2 < 3.0.14-2ubuntu0.1~esm1
Fix: upgrade to 3.0.14-2ubuntu0.1~esm1
Ubuntu:Pro:20.04:LTS canonical node-pbkdf2 < 3.0.16-1ubuntu0.1~esm1
Fix: upgrade to 3.0.16-1ubuntu0.1~esm1
Ubuntu:Pro:22.04:LTS canonical node-pbkdf2 < 3.1.2-2ubuntu0.1~esm1
Fix: upgrade to 3.1.2-2ubuntu0.1~esm1
Ubuntu:Pro:24.04:LTS canonical node-pbkdf2 < 3.1.2-3ubuntu0.1~esm1
Fix: upgrade to 3.1.2-3ubuntu0.1~esm1
Original title
node-pbkdf2 vulnerability
Original description
Nikita Skovoroda discovered that pbkdf2 did not properly validate
certain algorithm names. An attacker could possibly use this issue to
generate predictable cryptographic keys, resulting in signature spoofing.
Published: 18 Jun 2026 · Updated: 18 Jun 2026 · First seen: 18 Jun 2026