Among the 3 debian patches
available in version 3.1.6+~3.1.2-1 of the package,
we noticed the following issues:
1 patch
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.
1 issue left for the package maintainer to handle:
CVE-2025-6545:
(needs triaging)
Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
Migration status for node-pbkdf2 (3.1.5+~3.1.2-1 to 3.1.6+~3.1.2-1): Waiting for test results or another package, or too young (no action required now - check later)