CVE-2025-6545 Information

Description

Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability is associated with program files lib/to-buffer.Js.

This issue affects pbkdf2: from 3.0.10 through 3.1.2.

Reference

https://github.com/browserify/pbkdf2/commit/9699045c37a07f8319cfb8d44e2ff4252d7a7078 https://github.com/browserify/pbkdf2/commit/e3102a8cd4830a3ac85cd0dd011cc002fdde33bb https://github.com/browserify/pbkdf2/security/advisories/GHSA-h7cp-r72f-jxh6

CNNVD-202506-2928 (Published: 2025-06-23)

Share on: