Insufficient Entropy in cryptiles
Critical severity
GitHub Reviewed
Published
Sep 11, 2018
to the GitHub Advisory Database
•
Updated Jun 8, 2026
Package
Affected versions
>= 4.0.0, < 4.1.2
>= 3.1.0, < 3.1.3
Patched versions
4.1.2
3.1.3
Description
Published by the National Vulnerability Database
Jul 9, 2018
Published to the GitHub Advisory Database
Sep 11, 2018
Reviewed
Jun 16, 2020
Last updated
Jun 8, 2026
Versions of
cryptilesprior to 4.1.2 are vulnerable to Insufficient Entropy. TherandomDigits()method does not provide sufficient entropy and its generates digits that are not evenly distributed.Recommendation
Upgrade to version 4.1.2. The package is deprecated and has been moved to
@hapi/cryptilesand it is strongly recommended to use the maintained package.References