---
id: CVE-2023-46233
title: crypto-js is a JavaScript library of crypto standards
summary: >-
  crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0,
  crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and
  at least 1,300,000 times weaker than current industry standard. This is
  because …
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-328
  - CWE-916
  - CWE-327
vendor: crypto-js_project
product: crypto-js
affected:
  - crypto-js < 4.2.0
patched:
  - crypto-js 4.2.0
published: '2023-10-25'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-46233'
references:
  - url: >-
      https://github.com/brix/crypto-js/commit/421dd538b2d34e7c24a5b72cc64dc2b9167db40a
    label: security-advisories@github.com
  - url: 'https://github.com/brix/crypto-js/security/advisories/GHSA-xwcq-pm8m-c4vf'
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00025.html'
    label: security-advisories@github.com
  - url: >-
      https://github.com/brix/crypto-js/commit/421dd538b2d34e7c24a5b72cc64dc2b9167db40a
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/brix/crypto-js/security/advisories/GHSA-xwcq-pm8m-c4vf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/11/msg00025.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00635
epssPercentile: 0.49048
ingestedAt: '2026-06-29T13:24:33.919Z'
---

## Overview

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it both defaults to SHA1, a cryptographic hash algorithm considered insecure since at least 2005, and defaults to one single iteration, a 'strength' or 'difficulty' value specified at 1,000 when specified in 1993. PBKDF2 relies on iteration count as a countermeasure to preimage and collision attacks. If used to protect passwords, the impact is high. If used to generate signatures, the impact is high. Version 4.2.0 contains a patch for this issue. As a workaround, configure crypto-js to use SHA256 with at least 250,000 iterations.

## Affected

- `crypto-js < 4.2.0`

## Remediation

Upgrade past the affected range:

- `crypto-js 4.2.0`
