CVE-2026-105804: Payload: Password hashes use insufficient PBKDF2 iterations
Impact The password-hashing configuration used a lower work factor than what is recommended.
Patches Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.
Other sources
Payload is a free and open source headless content management system. Payload versions from 3.0.0 before 3.90.0 and canary versions from 4.0.0-canary.0 before 4.0.0-canary.34 use a lower-than-recommended PBKDF2 work factor for password hashing, reducing the computational effort required to test recovered password hashes. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34 - Upgrade
Upgrade
npm/payloadto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.90.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.0.0-canary.34 - Compensating control
Until upgrading, protect database copies and backups from unauthorized access and require strong, unique passwords.
Event History
Frequently Asked Questions
Which releases need to be upgraded?
Upgrade Payload 3.x to version 3.90.0 or later. For the canary line, upgrade to 4.0.0-canary.34 or later; affected ranges are 3.0.0 before 3.90.0 and 4.0.0-canary.0 before 4.0.0-canary.34.
What would an attacker need to take advantage of this issue?
An attacker would need access to recovered password hashes, such as through an unauthorized copy of the database or a backup. The lower work factor reduces the computational effort needed to test those hashes offline.
What should be done if an upgrade cannot be applied immediately?
Protect database copies and backups from unauthorized access, and require strong, unique passwords. Upgrading remains the recommended remediation.
What happens to existing password hashes after upgrading?
Payload transparently upgrades older hashes after a user successfully logs in. Hashes that have not yet been used for a successful login will not be upgraded through that process until the user logs in.