AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102414.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 06, 2026

Disclosure summary

### Summary This is the same bug as Django had (CVE-2013-1443). ### Details A long password can cause a DoS because it is not using cached HMAC, length limits, or pre-hashing passwords longer than the block size of the hash function as per HMAC spec. This line of code hashes the full password each iteration: https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/lib/sync.js#L60 Also see https://github.com/browserify/pbkdf2/issues/82 ### PoC The first key will take a lot longer to generate when not using the native code and uses code from `/lib/sync.js` (ie when this if statement is true): https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/index.js#L33-L37 ```js var pbkdf2 = require('pbkdf2'); var createHash = require('create-hash'); var pw = ".".repeat(1048576); // 1 MiB var t0 = performance.now(); var key1 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256"); var t1 = performance.now(); pw = createHash('sha256').update(pw).digest(); // HMAC specification for keys larger than block size var key2 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256"); var t2 = performance.now(); console.log("First took: " + (t1 - t0)); console.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-477h-4r7f-fvrx

Open original source · Updated Oct 06, 2026

pbkdf2 rehashes long passwords on every iteration, enabling denial of service

Source severity: MEDIUM / 6.3

EcosystemPackageAffected rangeFirst patched
npmpbkdf23.1.7

Original records & references

PUBLISHED 2026-10-06T09:40:10-04:00
MODIFIED 2026-10-06T09:40:10-04:00
INGESTED 2026-10-06T11:45:43-04:00