CVE-2026-94206: Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds
Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloakecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.
The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloakecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloakecto defaults (iterations: 600000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.
This issue affects cloakecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.
Affected Software
Event History
Frequently Asked Questions
What must an attacker obtain to take advantage of this issue?
The attacker needs both the hashed values and the configured secret. They can then perform offline brute-force guessing against low-entropy plaintexts.
Are default cloak_ecto configurations affected?
Yes. With the stated defaults of 600,000 iterations and a size of 32, hashes are computed with only 32 PBKDF2 rounds, making offline guesses about 18,750 times less costly than intended.
Which package versions should be considered affected?
Affected cloak_ecto versions begin at 1.0.0-alpha.0. Affected cloak versions begin at 0.7.0 and extend up to, but not including, 1.0.0-alpha.0.