Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 87%

CVE-2026-9641: CWE-916 Use of Password Hash With Insufficient Computational Effort in ARODLAND Crypt::PBKDF2

0
Medium
VulnerabilityCVE-2026-9641cvecve-2026-9641cwe-916
Published: 06/12/2026 (06/12/2026, 14:57:30 UTC)
Source: CVE Database V5
Vendor/Project: ARODLAND
Product: Crypt::PBKDF2

Description

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

CVSS v3.1

Score 5.3medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected software

GitHub Actionsmore threats →cve
Crypt-PBKDF2
pkg:github/Crypt-PBKDF2
Affected versions
<0.261630

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/19/2026, 18:22:22 UTC

Technical Analysis

CVE-2026-9641 identifies a weakness in Crypt::PBKDF2 versions before 0.261630 where the default password hashing algorithm is HMAC-SHA1 with only 1000 iterations. This iteration count is insufficient to provide adequate computational effort against brute-force attacks. The recommended iteration count ranges from 220,000 to 1,400,000 iterations depending on the algorithm, indicating that the default settings expose users to reduced password hashing strength.

Potential Impact

The vulnerability results in the use of a password hash with insufficient computational effort, reducing the effectiveness of password hashing against brute-force or dictionary attacks. This could lead to easier compromise of hashed passwords if attackers obtain them. The CVSS score of 5.3 (medium) reflects limited confidentiality impact with no integrity or availability impact.

Mitigation Recommendations

No official patch or remediation level is currently provided by the vendor. Users should upgrade to Crypt::PBKDF2 version 0.261630 or later where stronger defaults are expected. Until then, users should explicitly configure the module to use a stronger algorithm than HMAC-SHA1 and increase the iteration count to at least 220,000 iterations to improve password hashing strength.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CPANSec
Date Reserved
2026-05-26T18:44:37.132Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a2c283de617e2d83487db49

Added to database: 06/12/2026, 15:39:41 UTC

Last enriched: 06/19/2026, 18:22:22 UTC

Last updated: 07/31/2026, 19:23:00 UTC

Views: 97

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses