Source: node-pbkdf2 Version: 3.1.6+~3.1.2-1 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream Forwarded: https://github.com/browserify/pbkdf2/issues/82
Hi, The following vulnerability was published for node-pbkdf2. CVE-2026-102414[0]: | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's | block size on every iteration in its JavaScript fallback | (lib/sync.js). A password longer than the block size (64 bytes, or | 128 bytes for sha384 and sha512) is passed to HMAC as the key on | every iteration, and HMAC hashes such keys in full each time. Cost | is therefore O(iterations × password length), and a long password | can block the event loop. The fallback is used by pbkdf2Sync and | pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and | 1.2.6 and later), and on Deno 2.9.0 and later, because their native | pbkdf2Sync fails the library's feature check. It is also used when | lib/sync.js is imported directly. Node.js 0.12 and later, and | browser builds (which use lib/sync-browser.js), are not affected. | Applications that enforce a reasonable maximum password length are | not meaningfully affected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102414 https://www.cve.org/CVERecord?id=CVE-2026-102414 [1] https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx [2] https://github.com/browserify/pbkdf2/issues/82 [3] https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
