logo

Database

Javascript Predictable Iv Nonce Source

Description

This vulnerability detector identifies the use of predictable or weak initialization vectors (IVs) and nonces in JavaScript cryptographic operations. Using predictable IVs/nonces can compromise the security of encryption algorithms by making encrypted data susceptible to pattern analysis and cryptographic attacks.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • The detector scans JavaScript source code for cryptographic function calls that use initialization vectors or nonces

    • It identifies cases where IVs or nonces are generated using predictable sources such as hardcoded values, simple incremental counters, or weak random number generators

    • A vulnerability is reported when cryptographic operations use predictable or static IV/nonce values instead of cryptographically secure random values

    • The detection focuses on encryption functions, cipher initialization, and other cryptographic operations that require secure randomness for IVs or nonces

Vulnerable code example

const crypto = require('crypto');

function encryptData(key, data) {
  // VULNERABLE: IV derived from Date.now() is predictable to attackers
  const cipher = crypto.createCipheriv(
    'aes-256-cbc',
    key,
    Buffer.from(Date.now().toString().padStart(16, '0'))...

✅ Secure code example

const crypto = require('crypto');

function encryptData(key, data) {
  // SAFE: IV generated from crypto.randomBytes() is unpredictable
  const iv = crypto.randomBytes(16);
  const cipher = crypto.createCipheriv('aes-256-cbc', key, iv);
  const encrypted = Buffer.concat([cipher.update(data), cipher.final()]);
  // Return IV prepended to encrypted data for decryption...