pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to a version of pbkdf2 that includes the fix, which pre-hashes passwords longer than the digest block size once before iterating, or, enforce literally any reasonable maximum password length before calling pbkdf2.


Workaround

Enforce a maximum password length (for example, 1024 bytes) before calling pbkdf2, or call the runtime's native crypto.pbkdf2Sync directly.

History

Tue, 29 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Title pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: harborist

Published:

Updated: 2026-09-29T03:42:04.950Z

Reserved: 2026-09-29T02:06:16.561Z

Link: CVE-2026-102414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T04:17:55.180

Modified: 2026-09-29T04:17:55.180

Link: CVE-2026-102414

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T05:30:12Z

Weaknesses