logo

Database

Typescript Predictable Iv Nonce Source

Description

This vulnerability detector identifies the use of predictable or weak sources for initialization vectors (IVs) or nonces in TypeScript cryptographic operations. Predictable IVs/nonces can compromise the security of encryption algorithms, allowing attackers to potentially decrypt data or perform cryptographic attacks by exploiting the predictable values.

Weakness:

395 - Insecure generation of random numbers - Static IV

Category: Functionality Abuse

Detection Strategy

    • Scans TypeScript source code for cryptographic function calls that require initialization vectors or nonces

    • Identifies when IVs or nonces are generated using predictable sources such as hardcoded values, simple counters, current timestamps, or weak random number generators

    • Reports violations when cryptographic operations use deterministic or easily guessable values instead of cryptographically secure random sources

    • Flags usage of insecure IV/nonce generation patterns that could compromise encryption security

Vulnerable code example

import * as crypto from 'crypto';

function encryptWithPredictableIv(key: Buffer, data: Buffer): Buffer {
  // VULNERABLE: IV derived from Date.now() is predictable
  const cipher = crypto.createCipheriv(
    'aes-256-cbc',
    key,
    Buffer.from(Date.now().toString().padStart(16, '0'))...

✅ Secure code example

import * as crypto from 'crypto';

function encryptWithPredictableIv(key: Buffer, data: Buffer): Buffer {
  // SAFE: IV generated randomly instead of from predictable Date.now()
  const cipher = crypto.createCipheriv(
    'aes-256-cbc',
    key,
    crypto.randomBytes(16)  // Use cryptographically secure random IV...