crypto-js vulnerabilities
CVEs whose affected-version data names the crypto-js package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-71851Critical· 9.0PoCcrypto-js is a JavaScript library of crypto standards
crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded …
▾ Abyssalcrypto-js · crypto-jsEPSS 0.34%via NVD
CVE-2023-46233Critical· 9.1crypto-js is a JavaScript library of crypto standards
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …
▾ Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD