pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Summary
| CVE | CVE-2026-102414 |
|---|---|
| State | PUBLISHED |
| Assigner | harborist |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-29 04:17:55 UTC |
| Updated | 2026-09-29 04:17:55 UTC |
| Description | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected. |
Risk And Classification
Primary CVSS: v4.0 6.3 MEDIUM from 7ffcee3d-2c14-4c3e-b844-86c6a321a158
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-400 | CWE-400 CWE-400 Uncontrolled Resource Consumption
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 7ffcee3d-2c14-4c3e-b844-86c6a321a158 | Secondary | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
| 3.1 | 7ffcee3d-2c14-4c3e-b844-86c6a321a158 | Secondary | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
| 3.1 | CNA | CVSS | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Browserify | Pbkdf2 | affected 3.1.6 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx | 7ffcee3d-2c14-4c3e-b844-86c6a321a158 | github.com | |
| github.com/browserify/pbkdf2/issues/82 | 7ffcee3d-2c14-4c3e-b844-86c6a321a158 | github.com | |
| github.com/browserify/pbkdf2/commit/493d8d8 | 7ffcee3d-2c14-4c3e-b844-86c6a321a158 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Steve Thomas (Sc00bz) (en)
CNA: Jordan Harband (ljharb) (en)
Additional Advisory Data
Solutions
CNA: Upgrade to a version of pbkdf2 that includes the fix, which pre-hashes passwords longer than the digest block size once before iterating, or, enforce literally any reasonable maximum password length before calling pbkdf2.
Workarounds
CNA: Enforce a maximum password length (for example, 1024 bytes) before calling pbkdf2, or call the runtime's native crypto.pbkdf2Sync directly.