CVE-2026-102414: pbkdf2 rehashes long passwords on every iteration, enabling denial of service
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Enforce a reasonable maximum password length before calling pbkdf2 to prevent long passwords from blocking the event loop.
Event History
Frequently Asked Questions
Which deployments are affected by the JavaScript fallback?
Affected fallback use includes pbkdf2Sync and pbkdf2 on Node.js versions before 0.12, Bun 1.0.0 through 1.1.34 and 1.2.6 and later, and Deno 2.9.0 and later. Direct imports of lib/sync.js are also affected; Node.js 0.12 and later and browser builds using lib/sync-browser.js are not affected.
What must an attacker be able to do to cause the denial of service?
An attacker needs to cause the application to process a password longer than the digest block size while using the affected fallback. The relevant threshold is over 64 bytes for most digests, or over 128 bytes for sha384 and sha512; the impact increases with both password length and iteration count.
What mitigation is available if the library cannot be updated immediately?
Enforce a reasonable maximum password length before passing passwords to pbkdf2. Applications that already enforce a reasonable maximum password length are not meaningfully affected.