CVE-2026-102414 Details
Description
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
A denial-of-service vulnerability has been identified in the Browserify pbkdf2 library, affecting versions through 3.1.6. The issue arises in the JavaScript fallback of the library, where passwords longer than the digest's block size are rehashed on every iteration. This behavior can block the event loop, as the cost of processing such passwords is proportional to both the length of the password and the number of iterations specified. The vulnerability is present in Node.js versions prior to 0.12, as well as in Bun versions 1.0.0 through 1.1.34 and 1.2.6 and later. It also affects Deno 2.9.0 and later, when the native pbkdf2Sync function is unavailable. The problem can be reproduced by using a long password with the pbkdf2.pbkdf2Sync function, which will take significantly longer to process compared to a pre-hashed password of normal length.
Users can update to Browserify pbkdf2 version 3.1.7, which addresses the vulnerability by ensuring that long passwords are only hashed once, rather than on every iteration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx | CISA-ADP | AdvisoryRemedyVendor |
| https://github.com/browserify/pbkdf2/commit/493d8d8 | harborist | Source CodeVendor |
| https://github.com/browserify/pbkdf2/issues/82 | harborist | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx | harborist | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | harborist |
Affected Products
| Product | Versions |
|---|---|
| pbkdf2 | <= 3.1.6 (semver) |
CPE
Remediation
| |
| Node.js | All versions |
CPE
Remediation
| |
| Bun | All versions |
CPE
Remediation
| |
| Deno | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | harborist |
Volerion