pbkdf2 silently returns predictable uninitialized/zero-filled memory for non-normalized or unimplemented algos supported by Node.js
Published Jun 23, 2025
9.1
CRITICALCVSS 4.0
EPSS 0.45%
Description
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.
This issue affects pbkdf2: from 3.0.10 through 3.1.2.
Affected products
No data.
No data.
No data.
Red Hat Developer Hub 1.7
rhdh/rhdh-hub-rhel9:1.7.0-1754936470
Fixed · RHSA-2025:14090
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-api-rhel8:1771425314
Fixed · RHSA-2026:3710
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-api-rhel8:1771425314
Fixed · RHSA-2026:3712
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-db-migration-rhel8:1771964224
Fixed · RHSA-2026:3710
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-db-migration-rhel8:1771964224
Fixed · RHSA-2026:3712
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-ui-rhel8:1772036471
Fixed · RHSA-2026:3712
Red Hat OpenShift Pipelines 1.15
openshift-pipelines/pipelines-hub-ui-rhel8:1772036471
Fixed · RHSA-2026:3710
Red Hat OpenShift Pipelines 1.19
openshift-pipelines/pipelines-hub-db-migration-rhel9:v1.19.4-1764819005
Fixed · RHSA-2025:22905
Red Hat OpenShift Service Mesh 3.0
openshift-service-mesh/kiali-ossmc-rhel9:2.4.7-1751549390
Fixed · RHSA-2025:10738
Red Hat Trusted Artifact Signer 1.2
rhtas/rekor-search-ui-rhel9:1.2.1-1755456740
Fixed · RHSA-2025:14474
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-api-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8
Will not fix
OpenShift Service Mesh 3
openshift-service-mesh/kiali-operator-bundle
Will not fix
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9
Will not fix
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9-operator
Will not fix
Red Hat Developer Hub
rhdh/rhdh-rhel9-operator
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
pcs
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
pcs
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Fuse 7
io.apicurio-apicurito
Will not fix
Red Hat Fuse 7
io.syndesis-syndesis-parent
Will not fix
Red Hat Integration Camel K 1
io.apicurio-apicurio-registry
Will not fix
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-argoexec-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Will not fix
Red Hat OpenShift Container Platform 4
openshift4/ose-console-rhel9
Will not fix
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel8
Not affected
Red Hat OpenShift Dev Spaces
devspaces/dashboard-rhel9
Affected
Red Hat Process Automation 7
org.kie-process-migration-service
Not affected
Red Hat Process Automation 7
org.kie.workbench-kie-wb-common
Not affected
Red Hat Process Automation 7
org.uberfire-uberfire-parent
Not affected
Red Hat build of Apicurio Registry 2
io.apicurio-apicurio-registry
Affected
streams for Apache Kafka 2
com.github.streamshub-console
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Developer Hub 1.7 | rhdh/rhdh-hub-rhel9:1.7.0-1754936470 | Fixed | RHSA-2025:14090 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-api-rhel8:1771425314 | Fixed | RHSA-2026:3710 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-api-rhel8:1771425314 | Fixed | RHSA-2026:3712 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-db-migration-rhel8:1771964224 | Fixed | RHSA-2026:3710 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-db-migration-rhel8:1771964224 | Fixed | RHSA-2026:3712 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-ui-rhel8:1772036471 | Fixed | RHSA-2026:3712 |
| Red Hat OpenShift Pipelines 1.15 | openshift-pipelines/pipelines-hub-ui-rhel8:1772036471 | Fixed | RHSA-2026:3710 |
| Red Hat OpenShift Pipelines 1.19 | openshift-pipelines/pipelines-hub-db-migration-rhel9:v1.19.4-1764819005 | Fixed | RHSA-2025:22905 |
| Red Hat OpenShift Service Mesh 3.0 | openshift-service-mesh/kiali-ossmc-rhel9:2.4.7-1751549390 | Fixed | RHSA-2025:10738 |
| Red Hat Trusted Artifact Signer 1.2 | rhtas/rekor-search-ui-rhel9:1.2.1-1755456740 | Fixed | RHSA-2025:14474 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-api-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-operator-bundle | Will not fix | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9 | Will not fix | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9-operator | Will not fix | n/a |
| Red Hat Developer Hub | rhdh/rhdh-rhel9-operator | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Fuse 7 | io.apicurio-apicurito | Will not fix | n/a |
| Red Hat Fuse 7 | io.syndesis-syndesis-parent | Will not fix | n/a |
| Red Hat Integration Camel K 1 | io.apicurio-apicurio-registry | Will not fix | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-argoexec-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console-rhel9 | Will not fix | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel8 | Not affected | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/dashboard-rhel9 | Affected | n/a |
| Red Hat Process Automation 7 | org.kie-process-migration-service | Not affected | n/a |
| Red Hat Process Automation 7 | org.kie.workbench-kie-wb-common | Not affected | n/a |
| Red Hat Process Automation 7 | org.uberfire-uberfire-parent | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | io.apicurio-apicurio-registry | Affected | n/a |
| streams for Apache Kafka 2 | com.github.streamshub-console | Affected | n/a |
pbkdf2
npm
Introduced 3.0.10 Fixed 3.1.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | pbkdf2 | 3.0.10 | 3.1.3 |
Remediation
Red Hat statement
This flaw is rated important because it causes the pbkdf2 module to quietly return weak or zero-filled keys when certain algorithm names are used incorrectly in browsers or bundled code, this causes the function to silently return a predictable value (such as a zero-filled buffer or uninitialized memory) instead of a securely derived key, completely undermining the confidentiality and integrity of any cryptographic operation where attackers could guess or reuse these keys to access or change protected data.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-6545 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2374370 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18922 Advisory
- https://github.com/advisories/GHSA-h7cp-r72f-jxh6 Advisory
- https://github.com/browserify/pbkdf2/commit/9699045c37a07f8319cfb8d44e2ff4252d7a7078 x_introduced-by
- https://github.com/browserify/pbkdf2/commit/e3102a8cd4830a3ac85cd0dd011cc002fdde33bb patch
- https://github.com/browserify/pbkdf2/security/advisories/GHSA-h7cp-r72f-jxh6 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-6545
- https://www.cve.org/CVERecord?id=CVE-2025-6545
Change history (0)
No recorded changes yet.