Debian Package Tracker
Register | Log in
Subscribe

node-pbkdf2

RSA PKCS

Choose email to subscribe with

general
  • source: node-pbkdf2 (main)
  • version: 3.1.7+~3.1.2-1
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.1.1-1
  • oldstable: 3.1.2-3
  • stable: 3.1.2-3
  • testing: 3.1.6+~3.1.2-1
  • unstable: 3.1.7+~3.1.2-1
versioned links
  • 3.1.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.2-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.6+~3.1.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.1.7+~3.1.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-pbkdf2
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-102414: pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Created: 2026-09-30 Last update: 2026-10-03 15:48
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-102414: pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
1 issue postponed or untriaged:
  • CVE-2025-6545: (needs triaging) Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
Created: 2026-09-30 Last update: 2026-10-03 15:48
lintian reports 2 warnings normal
Lintian reports 2 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-09-21 Last update: 2026-09-21 04:00
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2025-6545: (needs triaging) Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js. This issue affects pbkdf2: from 3.0.10 through 3.1.2.
  • CVE-2026-102414: (needs triaging) pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.

You can find information about how to handle these issues in the security team's documentation.

Created: 2025-06-23 Last update: 2026-10-03 15:48
debian/patches: 1 patch to forward upstream low

Among the 3 debian patches available in version 3.1.7+~3.1.2-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-10-03 14:01
testing migrations
  • excuses:
    • Migration status for node-pbkdf2 (3.1.6+~3.1.2-1 to 3.1.7+~3.1.2-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for node-crypto-browserify/3.12.1-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for node-parse-asn1/5.1.9-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Autopkgtest for node-pbkdf2/3.1.7+~3.1.2-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Test triggered, s390x: Test triggered
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/n/node-pbkdf2.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-03] Accepted node-pbkdf2 3.1.7+~3.1.2-1 (source) into unstable (Xavier Guimard)
  • [2026-09-24] node-pbkdf2 3.1.6+~3.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-20] Accepted node-pbkdf2 3.1.6+~3.1.2-1 (source) into unstable (Xavier Guimard)
  • [2025-09-30] node-pbkdf2 3.1.5+~3.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-27] Accepted node-pbkdf2 3.1.5+~3.1.2-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2025-08-15] node-pbkdf2 3.1.3+~3.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-10] Accepted node-pbkdf2 3.1.3+~3.1.2-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-06-03] node-pbkdf2 3.1.2-3 MIGRATED to testing (Debian testing watch)
  • [2022-06-01] Accepted node-pbkdf2 3.1.2-3 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-01-29] node-pbkdf2 3.1.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-01-26] Accepted node-pbkdf2 3.1.2-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-01-22] node-pbkdf2 3.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-20] Accepted node-pbkdf2 3.1.2-1 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2022-01-19] Accepted node-pbkdf2 3.1.1-2 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2020-11-30] node-pbkdf2 3.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2020-11-27] Accepted node-pbkdf2 3.1.1-1 (source) into unstable (Xavier Guimard)
  • [2018-05-19] node-pbkdf2 3.0.16-1 MIGRATED to testing (Debian testing watch)
  • [2018-05-16] Accepted node-pbkdf2 3.0.16-1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2018-01-05] node-pbkdf2 3.0.14-2 MIGRATED to testing (Debian testing watch)
  • [2017-12-30] Accepted node-pbkdf2 3.0.14-2 (source) into unstable (Jérémy Lal)
  • [2017-09-20] node-pbkdf2 3.0.14-1 MIGRATED to testing (Debian testing watch)
  • [2017-09-14] Accepted node-pbkdf2 3.0.14-1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2017-08-26] node-pbkdf2 3.0.13-1 MIGRATED to testing (Debian testing watch)
  • [2017-08-20] Accepted node-pbkdf2 3.0.13-1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2017-06-20] node-pbkdf2 3.0.9-1 MIGRATED to testing (Debian testing watch)
  • [2017-05-07] Accepted node-pbkdf2 3.0.9-1 (source all) into unstable, unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 2)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.1.5+~3.1.2-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing