CVE-2026-9641: CWE-916 Use of Password Hash With Insufficient Computational Effort in ARODLAND Crypt::PBKDF2
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
AI Analysis
Technical Summary
CVE-2026-9641 identifies a weakness in Crypt::PBKDF2 versions before 0.261630 where the default password hashing algorithm is HMAC-SHA1 with only 1000 iterations. This iteration count is insufficient to provide adequate computational effort against brute-force attacks. The recommended iteration count ranges from 220,000 to 1,400,000 iterations depending on the algorithm, indicating that the default settings expose users to reduced password hashing strength.
Potential Impact
The vulnerability results in the use of a password hash with insufficient computational effort, reducing the effectiveness of password hashing against brute-force or dictionary attacks. This could lead to easier compromise of hashed passwords if attackers obtain them. The CVSS score of 5.3 (medium) reflects limited confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Users should upgrade to Crypt::PBKDF2 version 0.261630 or later where stronger defaults are expected. Until then, users should explicitly configure the module to use a stronger algorithm than HMAC-SHA1 and increase the iteration count to at least 220,000 iterations to improve password hashing strength.
CVE-2026-9641: CWE-916 Use of Password Hash With Insufficient Computational Effort in ARODLAND Crypt::PBKDF2
Description
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9641 identifies a weakness in Crypt::PBKDF2 versions before 0.261630 where the default password hashing algorithm is HMAC-SHA1 with only 1000 iterations. This iteration count is insufficient to provide adequate computational effort against brute-force attacks. The recommended iteration count ranges from 220,000 to 1,400,000 iterations depending on the algorithm, indicating that the default settings expose users to reduced password hashing strength.
Potential Impact
The vulnerability results in the use of a password hash with insufficient computational effort, reducing the effectiveness of password hashing against brute-force or dictionary attacks. This could lead to easier compromise of hashed passwords if attackers obtain them. The CVSS score of 5.3 (medium) reflects limited confidentiality impact with no integrity or availability impact.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Users should upgrade to Crypt::PBKDF2 version 0.261630 or later where stronger defaults are expected. Until then, users should explicitly configure the module to use a stronger algorithm than HMAC-SHA1 and increase the iteration count to at least 220,000 iterations to improve password hashing strength.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-05-26T18:44:37.132Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2c283de617e2d83487db49
Added to database: 06/12/2026, 15:39:41 UTC
Last enriched: 06/19/2026, 18:22:22 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 97
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.