CVE-2026-9641
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
| CWE | CWE-916 |
| Vendor | arodland |
| Product | crypt::pbkdf2 |
| Published | Jun 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for arodland crypt::pbkdf2
Be the first to know when new unknown vulnerabilities affecting arodland crypt::pbkdf2 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ARODLAND / Crypt::PBKDF2
0 < 0.261630