CVE-2026-102414
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Summary
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| browserify | pbkdf2 | 0 <= 3.1.6 | affected |
Weaknesses
- CWE-400: CWE-400 Uncontrolled Resource Consumption
Workarounds
Enforce a maximum password length (for example, 1024 bytes) before calling pbkdf2, or call the runtime's native crypto.pbkdf2Sync directly.
References
- https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx
- https://github.com/browserify/pbkdf2/issues/82
- https://github.com/browserify/pbkdf2/commit/493d8d8
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.