๐Ÿ” CVE Alert

CVE-2026-9641

MEDIUM 5.3

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
6th

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

CWE CWE-916
Vendor arodland
Product crypt::pbkdf2
Published Jun 12, 2026
Last Updated Jun 14, 2026
Stay Ahead of the Next One

Get instant alerts for arodland crypt::pbkdf2

Be the first to know when new medium vulnerabilities affecting arodland crypt::pbkdf2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ARODLAND / Crypt::PBKDF2
0 < 0.261630

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cheatsheetseries.owasp.org: https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2 metacpan.org: https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes openwall.com: http://www.openwall.com/lists/oss-security/2026/06/12/5 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/13/1 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/14/1 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/14/2 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/14/3