Javascript Key Derived Iv Nonce
Description
This vulnerability detector identifies JavaScript code that derives initialization vectors (IVs) or nonces from encryption keys. Using key-derived IVs/nonces is a cryptographic weakness that can lead to predictable values, compromising encryption security and potentially allowing attackers to decrypt sensitive data.
Detection Strategy
• Scans JavaScript source code for cryptographic implementations
• Identifies patterns where initialization vectors (IVs) or nonces are mathematically derived from encryption keys
• Flags code that generates IVs/nonces using key material as input to derivation functions
• Reports violations when cryptographic functions use non-random, key-dependent values for initialization parameters
Vulnerable code example
const crypto = require('crypto');
function encryptData(data) {
const key = crypto.randomBytes(16);
// VULNERABLE: IV reuses the same key bytes, breaking semantic security
const cipher = crypto.createCipheriv('aes-128-cbc', key, key);
return Buffer.concat([cipher.update(data), cipher.final()]);...✅ Secure code example
const crypto = require('crypto');
function encryptData(data) {
const key = crypto.randomBytes(16);
// SAFE: IV generated independently with randomBytes, not from key
const iv = crypto.randomBytes(16);
const cipher = crypto.createCipheriv('aes-128-cbc', key, iv);...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.