CVEs assigned by the Harborist CNA.
CVE ID | GHSA | Description |
---|---|---|
CVE-2025-6545 | GHSA-h7cp-r72f-jxh6 | Pbkdf2 Silently Returns Predictable Uninitialized/Zero-Filled Memory For Non-Normalized Or Unimplemented Algos Supported By Node.js |
CVE-2025-6547 | GHSA-v62p-rq8g-8h59 | On Node.js < 3, Pbkdf2 Silently Disregards Uint8Array Input, Returning Static Keys |