Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
Node Pbkdf2 Can Generate Predictable Cryptographic Keys
USN-8452-1
Summary
The Node Pbkdf2 library does not properly check certain algorithm names, which could allow an attacker to generate predictable cryptographic keys. This could be used to forge digital signatures. To fix this, update the Node Pbkdf2 library to the latest version, which includes a patch for this issue.
What to do
- Update canonical node-pbkdf2 to version 3.0.14-2ubuntu0.1~esm1.
- Update canonical node-pbkdf2 to version 3.0.16-1ubuntu0.1~esm1.
- Update canonical node-pbkdf2 to version 3.1.2-2ubuntu0.1~esm1.
- Update canonical node-pbkdf2 to version 3.1.2-3ubuntu0.1~esm1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:18.04:LTS | canonical | node-pbkdf2 |
< 3.0.14-2ubuntu0.1~esm1 Fix: upgrade to 3.0.14-2ubuntu0.1~esm1
|
| Ubuntu:Pro:20.04:LTS | canonical | node-pbkdf2 |
< 3.0.16-1ubuntu0.1~esm1 Fix: upgrade to 3.0.16-1ubuntu0.1~esm1
|
| Ubuntu:Pro:22.04:LTS | canonical | node-pbkdf2 |
< 3.1.2-2ubuntu0.1~esm1 Fix: upgrade to 3.1.2-2ubuntu0.1~esm1
|
| Ubuntu:Pro:24.04:LTS | canonical | node-pbkdf2 |
< 3.1.2-3ubuntu0.1~esm1 Fix: upgrade to 3.1.2-3ubuntu0.1~esm1
|
Original title
node-pbkdf2 vulnerability
Original description
Nikita Skovoroda discovered that pbkdf2 did not properly validate
certain algorithm names. An attacker could possibly use this issue to
generate predictable cryptographic keys, resulting in signature spoofing.
certain algorithm names. An attacker could possibly use this issue to
generate predictable cryptographic keys, resulting in signature spoofing.
- https://ubuntu.com/security/notices/USN-8452-1 Vendor Advisory
- https://ubuntu.com/security/CVE-2025-6545 Third Party Advisory
Published: 18 Jun 2026 · Updated: 18 Jun 2026 · First seen: 18 Jun 2026