CVE Explorer
CVE-2026-9641
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
The default algorithm is HMAC-SHA1, which should only be used for legacy systems.
These versions default to using 1000 iterations.
Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","packageName":"Crypt-PBKDF2","product":"Crypt::PBKDF2","repo":"https://github.com/arodland/Crypt-PBKDF2","vendor":"ARODLAND","versions":[{"lessThan":"0.261630","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-916","description":"CWE-916 Use of Password Hash With Insufficient Computational Effort","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/cna/problemTypes/0/descriptions/0
Source references
7 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/06/12/5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/1/references/0
{"url":"http://www.openwall.com/lists/oss-security/2026/06/13/1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/1/references/1
{"url":"http://www.openwall.com/lists/oss-security/2026/06/14/1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/1/references/2
{"url":"http://www.openwall.com/lists/oss-security/2026/06/14/2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/1/references/3
{"url":"http://www.openwall.com/lists/oss-security/2026/06/14/3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/adp/1/references/4
{"tags":["technical-description"],"url":"https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#pbkdf2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/cna/references/0
{"tags":["release-notes"],"url":"https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1a7f37e4c5d416c34b7aafd4723c8f184286a28d278c9efa605c1f324f9751ae · sha256:665d76134befa30c… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.