Description
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Published: 2026-09-29
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service through event loop blocking
Action: Patch
AI Analysis

Impact

pbkdf2’s JavaScript fallback recreates the password key in the HMAC function on every iteration when the password exceeds the digest block size. The cost of each iteration scales with password length, making the total time O(iterations × password length). An attacker can supply an arbitrarily long password to delay or stall the event loop, effectively causing a denial of service to any application that calls pbkdf2Sync or pbkdf2 under the vulnerable conditions.

Affected Systems

The affected component is the browserify pbkdf2 library through version 3.1.6. The vulnerability is triggered when the library’s JavaScript fallback (lib/sync.js) is used. This occurs with pbkdf2Sync and pbkdf2 on Node.js versions earlier than 0.12, on Bun 1.0.0 through 1.1.34 and 1.2.6 and later, and on Deno 2.9.0 and later, because those runtimes’ native implementations fail the library’s feature check. Browser builds that use lib/sync-browser.js and Node.js 0.12 and later are not affected.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in CISA KEV. Exploitation is possible by any entity that can invoke the vulnerable pbkdf2 function with a sufficiently long password, which may be through a public API, authentication, or other interface. The mitigation most directly addresses the root cause by preventing repeated hashing of long keys; without it an attacker could repeatedly stall the event loop, consuming CPU and memory resources and potentially impacting other concurrent processes.

Generated by OpenCVE AI on September 29, 2026 at 05:23 UTC.

Remediation

Vendor Solution

Upgrade to a version of pbkdf2 that includes the fix, which pre-hashes passwords longer than the digest block size once before iterating, or, enforce literally any reasonable maximum password length before calling pbkdf2.


Vendor Workaround

Enforce a maximum password length (for example, 1024 bytes) before calling pbkdf2, or call the runtime's native crypto.pbkdf2Sync directly.


OpenCVE Recommended Actions

  • Upgrade the pbkdf2 package to a version that implements the pre‑hashing fix (≥ 3.1.7).
  • If an upgrade cannot be performed immediately, enforce a maximum password length (e.g., 1024 bytes) before calling pbkdf2 to avoid the vulnerable path.
  • In Node.js or Bun applications, replace calls to pbkdf2Sync with the runtime’s native crypto.pbkdf2Sync to bypass the JavaScript fallback.
  • Ensure that lib/sync.js is not imported directly; use the library’s default export so that the environment’s native implementation is chosen when available.

Generated by OpenCVE AI on September 29, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Title pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: harborist

Published:

Updated: 2026-09-29T03:42:04.950Z

Reserved: 2026-09-29T02:06:16.561Z

Link: CVE-2026-102414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T04:17:55.180

Modified: 2026-09-29T04:17:55.180

Link: CVE-2026-102414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T05:30:12Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption