Sceawere
Vulnerability Detail
CVE-2026-102414UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PBKDF2 Re-hash Denial of Service
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 3h ago
- Vendor
- browserify
- Product
- pbkdf2
- Attack Type
- CWE-400 Uncontrolled Resource Consumption
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on every iteration, and HMAC hashes such keys in full each time. Cost is therefore O(iterations × password length), and a long password can block the event loop. The fallback is used by pbkdf2Sync and pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and 1.2.6 and later), and on Deno 2.9.0 and later, because their native pbkdf2Sync fails the library's feature check. It is also used when lib/sync.js is imported directly. Node.js 0.12 and later, and browser builds (which use lib/sync-browser.js), are not affected. Applications that enforce a reasonable maximum password length are not meaningfully affected.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-29T04:17:55.180Z",
"pubdate": "2026-09-29T04:17:55.180Z",
"executiveSummary": "The pbkdf2 JavaScript library exhibits a vulnerability where passwords exceeding the digest's block size trigger excessive re-hashing during each iteration of the PBKDF2 algorithm within the lib/sync.js fallback implementation.\nThis design flaw leads to an O(iterations × password length) computational complexity, which can be exploited to cause significant CPU exhaustion.\nThe vulnerability affects systems relying on the JavaScript fallback, specifically environments where native PBKDF2 support is bypassed or unavailable, such as Bun (1.0.0 through 1.1.34, and 1.2.6 and later), Deno (2.9.0 and later), and legacy Node.js environments (before 0.12).\nBecause Node.js is single-threaded, an attacker providing an excessively long password can block the event loop, effectively causing a Denial of Service (DoS) for the entire application.\nRisk is primarily associated with applications that do not enforce input length validation on user-provided passwords.\nNo specific authentication or privilege escalation is required to trigger this vulnerability, as the input processing occurs during the standard key derivation phase.",
"technicalDetails": "The root cause of this vulnerability lies in the implementation of the HMAC-based Key Derivation Function (PBKDF2) within lib/sync.js. In standard PBKDF2 implementations, passwords exceeding the underlying HMAC block size (64 bytes for SHA-256, 128 bytes for SHA-384/512) are typically pre-hashed before being used as the HMAC key.\nThe vulnerable library fails to implement this pre-hashing step correctly in the JS fallback. Instead, the implementation passes the full-length password as the key to the HMAC function on every single iteration. Consequently, the HMAC function is forced to process the entire length of the password string in every iteration of the derivation cycle.\nThe computational cost scales linearly with both the number of iterations and the length of the password string (O(iterations × length)). When a sufficiently long password is submitted, the CPU cycles required for a single derivation request increase dramatically.\nBecause this specific fallback (lib/sync.js) executes synchronously, it occupies the execution thread completely. In the context of Node.js, Bun, and Deno, this results in the blocking of the event loop. The event loop cannot process other incoming network requests, timers, or I/O operations while the CPU is locked in this derivation loop.\nAttack flow involves an unauthenticated or authenticated user providing a deliberately long password string (significantly exceeding 64 or 128 bytes) in a login or authentication field. When the application calls pbkdf2 or pbkdf2Sync, the library triggers the synchronous fallback. The process becomes unresponsive, consuming CPU resources for an extended duration depending on the configured iteration count, thereby denying service to other legitimate users.\nThe vulnerability is limited to the lib/sync.js implementation and does not affect browser-based builds utilizing lib/sync-browser.js or modern Node.js versions (0.12+) that correctly leverage native, optimized C++ bindings for PBKDF2, which handle block-size constraints according to standard specifications.\nImpact is primarily a Denial of Service. While the complexity is high, it does not lead to remote code execution or unauthorized memory access, but it effectively halts all service functionality until the derivation process completes or the process is forcibly terminated by the operating system or monitoring watchdog."
}