๐Ÿ” CVE Alert

CVE-2026-102414

LOW 3.7

pbkdf2 rehashes long passwords on every iteration, enabling denial of service

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations ร— password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.

CWE CWE-400
Vendor browserify
Product pbkdf2
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for browserify pbkdf2

Be the first to know when new low vulnerabilities affecting browserify pbkdf2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

browserify / pbkdf2
0 โ‰ค 3.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx github.com: https://github.com/browserify/pbkdf2/issues/82 github.com: https://github.com/browserify/pbkdf2/commit/493d8d8

Credits

Steve Thomas (Sc00bz) Jordan Harband (ljharb)