Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Jun 14, 2026
CVE-2026-9641
CVE-2026-9641
Description
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
The default algorithm is HMAC-SHA1, which should only be used for legacy systems.
These versions default to using 1000 iterations.
Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2026/06/12/5nvd
- www.openwall.com/lists/oss-security/2026/06/13/1nvd
- www.openwall.com/lists/oss-security/2026/06/14/1nvd
- www.openwall.com/lists/oss-security/2026/06/14/2nvd
- www.openwall.com/lists/oss-security/2026/06/14/3nvd
- cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.htmlnvd
- metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changesnvd
News mentions
0No linked articles in our index yet.