Resource exhaustion in PBKDF2 - CVE-2026-102414
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the PBKDF2 synchronous implementation when deriving keys from long passwords. A remote attacker can supply a long password to cause a denial of service.
The issue occurs when the native code path is not used.