CVE-2026-9641

EUVD-2026-36470
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.

The default algorithm is HMAC-SHA1, which should only be used for legacy systems.

These versions default to using 1000 iterations.

Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 13.21%
Debian logo
Debian Releases
Debian Product
Codename
libcrypt-pbkdf2-perl
bookworm
0.261630-1~deb13u1~deb12u1
fixed
forky
0.261630-1
fixed
sid
0.261630-1
fixed
trixie
0.261630-1~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libcrypt-pbkdf2-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
perl-Crypt-PBKDF2
Amazon Linux 2023
0:0.261630-1.amzn2023.0.1
fixed