- Package:
- src:node-pbkdf2
- Source:
- src:node-pbkdf2
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-03 07:07:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for node-pbkdf2. CVE-2026-102414[0]: | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's | block size on every iteration in its JavaScript fallback | (lib/sync.js). A password longer than the block size (64 bytes, or | 128 bytes for sha384 and sha512) is passed to HMAC as the key on | every iteration, and HMAC hashes such keys in full each time. Cost | is therefore O(iterations × password length), and a long password | can block the event loop. The fallback is used by pbkdf2Sync and | pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and | 1.2.6 and later), and on Deno 2.9.0 and later, because their native | pbkdf2Sync fails the library's feature check. It is also used when | lib/sync.js is imported directly. Node.js 0.12 and later, and | browser builds (which use lib/sync-browser.js), are not affected. | Applications that enforce a reasonable maximum password length are | not meaningfully affected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102414 https://www.cve.org/CVERecord?id=CVE-2026-102414 [1] https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx [2] https://github.com/browserify/pbkdf2/issues/82 [3] https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1149792 in node-pbkdf2 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-pbkdf2/-/commit/4965c2d328293669b941e252ebad44896d673165 (this message was generated automatically) -- Greetings https://bugs.debian.org/1149792
Hello, Bug #1149792 in node-pbkdf2 reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/js-team/node-pbkdf2/-/commit/4965c2d328293669b941e252ebad44896d673165 (this message was generated automatically) -- Greetings https://bugs.debian.org/1149792
We believe that the bug you reported is fixed in the latest version of node-pbkdf2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1149792@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated node-pbkdf2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Sat, 03 Oct 2026 08:36:44 +0200 Source: node-pbkdf2 Architecture: source Version: 3.1.7+~3.1.2-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1149792 Changes: node-pbkdf2 (3.1.7+~3.1.2-1) unstable; urgency=medium . * Team upload * New upstream release (Closes: #1149792, CVE-2026-102414) Checksums-Sha1: 0a9fc3c3107932206d239b5e75d7e780fc09f5fd 2528 node-pbkdf2_3.1.7+~3.1.2-1.dsc 2dc43808e9985a2c69ff02e2d2027bd4fe33e8dc 1777 node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz 3b15328ae14a1cf3420d2bd4a9c48b274a452658 27060 node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz df4f851c9f4a6c068123fa827da996b48e48f67f 5224 node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz Checksums-Sha256: a63bb4b990c81a56f34bcea808f0d63078c5136728957049827e613df6fa9a1f 2528 node-pbkdf2_3.1.7+~3.1.2-1.dsc 8f5b884c96b470207fb88b99e54a806886df090e55ea33f832f7dd22c203e041 1777 node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz 5c703ac1df95e210f551dbb80545457de13d08570ffcb6a196e7eae5897b1107 27060 node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz 34be2d23f04f379289eeb8cd36db771dbaefd4b168b94ae862c3785802ae709e 5224 node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz Files: 22f5f164703f49f71c875208295483fc 2528 javascript optional node-pbkdf2_3.1.7+~3.1.2-1.dsc c7af94f3166ae211d097fc42e6ee1321 1777 javascript optional node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz 1c4426099db485b33f8c08fdbbd060fb 27060 javascript optional node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz ff794b71362fed844fad8bb9d7f1f460 5224 javascript optional node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAovMACgkQ9tdMp8mZ 7un50Q/9EkRyHHm9CpF8r0lJ4YiEj2fjQB3I5VY9fxTS7awJxHnCMFFgClGgrPDz ScWFSmd9nPwC7CgzfVU+3uHlv985SAxZkJ23KHkM5UVxlW3IDJxusk3Lr4sQV7s/ qxrdqkWFw6R8svKAiYLry0JDhYlww/XSYQB88XZM8lli3vN4m7EEQYwsMEiu/oQQ 8VLBfllQhFZ8awfQsOjcDvNAkjHn8vYDMD+yuiELk002vZX3cQwtLS7y070HTrRO 8+a9d7o7bC15KBTy1ext1k1eRxpnAap+VwNiq5giCx8fl7jcMrSIOMh1eeXIKtGm ppnGp7h89wgoDuc4l2MXAFnq51c02qJUkOyVv2yfiaClYqaILNVzco1vKjwJCMlt k3JFirlnfhvlYsIyr0KKjX4CjxCMeIzBAMvaZrqbOLvvMiOD7D6AuTXB8Py5OIwN x95VV5xdUemP3xClpmDBjup8L6wypkhYb/uvl7wRM0uco8sKQvqiOQ9juDMiFDjm BPzG1yJAG3iGidFojHG8ELGXlExbrWcMEcZ46szOh9mFMAiBa7wO2ha0dLEZmTkT QQGcb3gkbITMHmp3OUOUTtK5V++CgcVeazihrfyAMcbKRQlT+oIIN1Fbg5Ov/T3p tvNDlCfqR6R/s9pvjIHu9+/s5AI+OC/PkxHXYHk8vcvTIfpSams= =bQ7V -----END PGP SIGNATURE-----