CVE-2026-102414

CVE-2026-102414 published: pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallback (lib/sync.js). A password longer than the block size (64 bytes, or 128 bytes for sha384 and sha512) is passed to HMAC as the key on ev...

View full NVD advisory → ← Back to CVE watch