Source: node-pbkdf2
Version: 3.1.6+~3.1.2-1
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream
Forwarded: https://github.com/browserify/pbkdf2/issues/82

Hi,

The following vulnerability was published for node-pbkdf2.

CVE-2026-102414[0]:
| pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's
| block size on every iteration in its JavaScript fallback
| (lib/sync.js). A password longer than the block size (64 bytes, or
| 128 bytes for sha384 and sha512) is passed to HMAC as the key on
| every iteration, and HMAC hashes such keys in full each time. Cost
| is therefore O(iterations × password length), and a long password
| can block the event loop. The fallback is used by pbkdf2Sync and
| pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and
| 1.2.6 and later), and on Deno 2.9.0 and later, because their native
| pbkdf2Sync fails the library's feature check. It is also used when
| lib/sync.js is imported directly. Node.js 0.12 and later, and
| browser builds (which use lib/sync-browser.js), are not affected.
| Applications that enforce a reasonable maximum password length are
| not meaningfully affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102414
    https://www.cve.org/CVERecord?id=CVE-2026-102414
[1] https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx
[2] https://github.com/browserify/pbkdf2/issues/82
[3] 
https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to