MEDIUM
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations
Published Jun 12, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.29%
Description
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
The default algorithm is HMAC-SHA1, which should only be used for legacy systems.
These versions default to using 1000 iterations.
Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
Affected products
-
- Version 0StatusaffectedConstraints<0.261630
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Arodland | Crypt::PBKDF2 | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 0.261630 or later.
Weaknesses (1)
References (7)
- http://www.openwall.com/lists/oss-security/2026/06/12/5
- http://www.openwall.com/lists/oss-security/2026/06/13/1
- http://www.openwall.com/lists/oss-security/2026/06/14/1
- http://www.openwall.com/lists/oss-security/2026/06/14/2
- http://www.openwall.com/lists/oss-security/2026/06/14/3
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2 technical-description
- https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes release-notes
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CPANSec
Published Jun 12, 2026
Updated Jun 14, 2026
Reserved May 26, 2026
Link CVE-2026-9641
CISA Vulnrichment
Updated Jun 12, 2026