Skip to content

Uninitialized DH computeSecret should throw instead of returning empty buffers #63674

Description

@ChALkeR

When a DH instance does not have a private key initialized, it just happily returns empty buffers for all public keys.

That is a footgun and needs to be fixed (turned into a throw).

Welcome to Node.js v26.2.0.
Type ".help" for more information.
> require('crypto').createDiffieHellman(512).computeSecret(Buffer.alloc(64,1))
<Buffer >

See also #62838

Activity

  1. added
    cryptoIssues and PRs related to the crypto subsystem.
    on May 31, 2026
  2. Anshikakalpana commented on May 31, 2026

    @Anshikakalpana
    Contributor

    @ChALkeR I worked on the same pattern in #62838 and #63162. Happy to take this — will follow the same runtime deprecation approach

  3. ChALkeR commented on May 31, 2026

    @ChALkeR
    MemberAuthor

    I think this one can go straight to error instead of deprecation
    @panva thoughs?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions