Impact
pbkdf2’s JavaScript fallback recreates the password key in the HMAC function on every iteration when the password exceeds the digest block size. The cost of each iteration scales with password length, making the total time O(iterations × password length). An attacker can supply an arbitrarily long password to delay or stall the event loop, effectively causing a denial of service to any application that calls pbkdf2Sync or pbkdf2 under the vulnerable conditions.
Affected Systems
The affected component is the browserify pbkdf2 library through version 3.1.6. The vulnerability is triggered when the library’s JavaScript fallback (lib/sync.js) is used. This occurs with pbkdf2Sync and pbkdf2 on Node.js versions earlier than 0.12, on Bun 1.0.0 through 1.1.34 and 1.2.6 and later, and on Deno 2.9.0 and later, because those runtimes’ native implementations fail the library’s feature check. Browser builds that use lib/sync-browser.js and Node.js 0.12 and later are not affected.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in CISA KEV. Exploitation is possible by any entity that can invoke the vulnerable pbkdf2 function with a sufficiently long password, which may be through a public API, authentication, or other interface. The mitigation most directly addresses the root cause by preventing repeated hashing of long keys; without it an attacker could repeatedly stall the event loop, consuming CPU and memory resources and potentially impacting other concurrent processes.
OpenCVE Enrichment