#1149792 node-pbkdf2: CVE-2026-102414

Package:
src:node-pbkdf2
Source:
src:node-pbkdf2
Submitter:
Salvatore Bonaccorso
Date:
2026-10-03 07:07:04 UTC
Severity:
normal
Tags:
#1149792#5
Date:
2026-10-03 06:26:52 UTC
From:
To:
Hi,

The following vulnerability was published for node-pbkdf2.

CVE-2026-102414[0]:
| pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's
| block size on every iteration in its JavaScript fallback
| (lib/sync.js). A password longer than the block size (64 bytes, or
| 128 bytes for sha384 and sha512) is passed to HMAC as the key on
| every iteration, and HMAC hashes such keys in full each time. Cost
| is therefore O(iterations × password length), and a long password
| can block the event loop. The fallback is used by pbkdf2Sync and
| pbkdf2 on Node.js before 0.12, on Bun (1.0.0 through 1.1.34, and
| 1.2.6 and later), and on Deno 2.9.0 and later, because their native
| pbkdf2Sync fails the library's feature check. It is also used when
| lib/sync.js is imported directly. Node.js 0.12 and later, and
| browser builds (which use lib/sync-browser.js), are not affected.
| Applications that enforce a reasonable maximum password length are
| not meaningfully affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102414
https://www.cve.org/CVERecord?id=CVE-2026-102414
[1] https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx
[2] https://github.com/browserify/pbkdf2/issues/82
[3] https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149792#8
Date:
2026-10-03 06:39:31 UTC
From:
To:
Hello,

Bug #1149792 in node-pbkdf2 reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-pbkdf2/-/commit/4965c2d328293669b941e252ebad44896d673165

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149792

#1149792#13
Date:
2026-10-03 06:39:29 UTC
From:
To:
Hello,

Bug #1149792 in node-pbkdf2 reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/js-team/node-pbkdf2/-/commit/4965c2d328293669b941e252ebad44896d673165

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1149792

#1149792#18
Date:
2026-10-03 07:05:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
node-pbkdf2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149792@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated node-pbkdf2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 03 Oct 2026 08:36:44 +0200
Source: node-pbkdf2
Architecture: source
Version: 3.1.7+~3.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1149792
Changes:
 node-pbkdf2 (3.1.7+~3.1.2-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream release (Closes: #1149792, CVE-2026-102414)
Checksums-Sha1:
 0a9fc3c3107932206d239b5e75d7e780fc09f5fd 2528 node-pbkdf2_3.1.7+~3.1.2-1.dsc
 2dc43808e9985a2c69ff02e2d2027bd4fe33e8dc 1777 node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 3b15328ae14a1cf3420d2bd4a9c48b274a452658 27060 node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 df4f851c9f4a6c068123fa827da996b48e48f67f 5224 node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz
Checksums-Sha256:
 a63bb4b990c81a56f34bcea808f0d63078c5136728957049827e613df6fa9a1f 2528 node-pbkdf2_3.1.7+~3.1.2-1.dsc
 8f5b884c96b470207fb88b99e54a806886df090e55ea33f832f7dd22c203e041 1777 node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 5c703ac1df95e210f551dbb80545457de13d08570ffcb6a196e7eae5897b1107 27060 node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 34be2d23f04f379289eeb8cd36db771dbaefd4b168b94ae862c3785802ae709e 5224 node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz
Files:
 22f5f164703f49f71c875208295483fc 2528 javascript optional node-pbkdf2_3.1.7+~3.1.2-1.dsc
 c7af94f3166ae211d097fc42e6ee1321 1777 javascript optional node-pbkdf2_3.1.7+~3.1.2.orig-types-pbkdf2.tar.gz
 1c4426099db485b33f8c08fdbbd060fb 27060 javascript optional node-pbkdf2_3.1.7+~3.1.2.orig.tar.gz
 ff794b71362fed844fad8bb9d7f1f460 5224 javascript optional node-pbkdf2_3.1.7+~3.1.2-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrAovMACgkQ9tdMp8mZ
7un50Q/9EkRyHHm9CpF8r0lJ4YiEj2fjQB3I5VY9fxTS7awJxHnCMFFgClGgrPDz
ScWFSmd9nPwC7CgzfVU+3uHlv985SAxZkJ23KHkM5UVxlW3IDJxusk3Lr4sQV7s/
qxrdqkWFw6R8svKAiYLry0JDhYlww/XSYQB88XZM8lli3vN4m7EEQYwsMEiu/oQQ
8VLBfllQhFZ8awfQsOjcDvNAkjHn8vYDMD+yuiELk002vZX3cQwtLS7y070HTrRO
8+a9d7o7bC15KBTy1ext1k1eRxpnAap+VwNiq5giCx8fl7jcMrSIOMh1eeXIKtGm
ppnGp7h89wgoDuc4l2MXAFnq51c02qJUkOyVv2yfiaClYqaILNVzco1vKjwJCMlt
k3JFirlnfhvlYsIyr0KKjX4CjxCMeIzBAMvaZrqbOLvvMiOD7D6AuTXB8Py5OIwN
x95VV5xdUemP3xClpmDBjup8L6wypkhYb/uvl7wRM0uco8sKQvqiOQ9juDMiFDjm
BPzG1yJAG3iGidFojHG8ELGXlExbrWcMEcZ46szOh9mFMAiBa7wO2ha0dLEZmTkT
QQGcb3gkbITMHmp3OUOUTtK5V++CgcVeazihrfyAMcbKRQlT+oIIN1Fbg5Ov/T3p
tvNDlCfqR6R/s9pvjIHu9+/s5AI+OC/PkxHXYHk8vcvTIfpSams=
=bQ7V
-----END PGP SIGNATURE-----