CVE-2026-102414: pbkdf2 rehashes long passwords on every iteration, enabling denial of service

Published Sep 29, 2026
·
Updated

pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.

Affected Software

1 affected component
npm/pbkdf2<=3.1.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Enforce a reasonable maximum password length before calling pbkdf2 to prevent long passwords from blocking the event loop.

Event History

Sep 29, 2026
CVE Published
via MITRE·03:42 AM
Data Sourced
via MITRE·03:42 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected by the JavaScript fallback?

Affected fallback use includes pbkdf2Sync and pbkdf2 on Node.js versions before 0.12, Bun 1.0.0 through 1.1.34 and 1.2.6 and later, and Deno 2.9.0 and later. Direct imports of lib/sync.js are also affected; Node.js 0.12 and later and browser builds using lib/sync-browser.js are not affected.

2

What must an attacker be able to do to cause the denial of service?

An attacker needs to cause the application to process a password longer than the digest block size while using the affected fallback. The relevant threshold is over 64 bytes for most digests, or over 128 bytes for sha384 and sha512; the impact increases with both password length and iteration count.

3

What mitigation is available if the library cannot be updated immediately?

Enforce a reasonable maximum password length before passing passwords to pbkdf2. Applications that already enforce a reasonable maximum password length are not meaningfully affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203