Executive brief
The pbkdf2 JavaScript library used in browsers and bundled applications silently returns predictable, zero-filled buffers when deriving cryptographic keys with unsupported or non-normalized algorithm names (e.g., "SHA-256" instead of "sha256"), even though these algorithms work correctly in Node.js. This means applications using variant algorithm names receive weak, guessable key material instead of proper cryptographic output, severely compromising password-based encryption, authentication tokens, and other secrets derived through pbkdf2.
Technical details
This is an input validation and cryptographic fallback bug in the pbkdf2 npm package (versions 3.0.10 to 3.1.2). The vulnerable component fails to normalize algorithm names (e.g., accepting "Sha256" or "SHA-256" in addition to the canonical "sha256") or validate against unsupported algorithms (e.g., "sha3-512", "blake2b512"). When an unknown or non-normalized name is passed, the library returns a zero-filled buffer in browsers or uninitialized memory via Buffer.allocUnsafe in Node.js/Bun, rather than throwing an error. The attack vector is application-level: developers unknowingly passing variant algorithm names or attempting to use unsupported but theoretically compatible algorithms receive completely predictable output. No network access, authentication, or user interaction is required—the flaw triggers silently on any call with a non-whitelisted algorithm string. The patch (version 3.1.3+) enforces strict algorithm name validation.
Affected products
- browserify pbkdf2 >=3.0.10, <=3.1.2
Timeline
- 2025-06-23: disclosed: Advisory published GHSA-h7cp-r72f-jxh6 and CVE-2025-6545
- 2025-06-23: patched: Fix released in pbkdf2 version 3.1.3+