Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to a version of pbkdf2 that includes the fix, which pre-hashes passwords longer than the digest block size once before iterating, or, enforce literally any reasonable maximum password length before calling pbkdf2.
Vendor Workaround
Enforce a maximum password length (for example, 1024 bytes) before calling pbkdf2, or call the runtime's native crypto.pbkdf2Sync directly.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected. | |
| Title | pbkdf2 rehashes long passwords on every iteration, enabling denial of service | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: harborist
Published:
Updated: 2026-09-29T03:42:04.950Z
Reserved: 2026-09-29T02:06:16.561Z
Link: CVE-2026-102414
No data.
Status : Received
Published: 2026-09-29T04:17:55.180
Modified: 2026-09-29T04:17:55.180
Link: CVE-2026-102414
No data.
OpenCVE Enrichment
Updated: 2026-09-29T05:30:12Z