Vulnerability Description
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html
- https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes
- http://www.openwall.com/lists/oss-security/2026/06/12/5
- http://www.openwall.com/lists/oss-security/2026/06/13/1
- http://www.openwall.com/lists/oss-security/2026/06/14/1
- http://www.openwall.com/lists/oss-security/2026/06/14/2
- http://www.openwall.com/lists/oss-security/2026/06/14/3
FAQ
What is CVE-2026-9641?
CVE-2026-9641 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versio...
How severe is CVE-2026-9641?
CVE-2026-9641 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9641?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.