216.73.217.22

CVE-2026-9641

· Published 12/06/2026 18:16 · Modified 13/06/2026 04:17 · Author: The MITRE Corporation

Labels: CVE-2026-9641 2026-06-129b29abf9-4ab0-4765-b253-1875cd9b441eCVE-2026-9641CWE-916

Essential information

Published
12/06/2026 18:16
Modified
13/06/2026 04:17
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CWE-916
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.

NVD status

Status
Deferred — When a CVE is given this status the NVD does not plan analyze or re-analyze this CVE due to resource or other concerns.
Source
9b29abf9-4ab0-4765-b253-1875cd9b441e
NVD
View on NVD

Affected products (CPE)

ProductCPE
perl / crypt cpe:2.3:a:perl:crypt::pbkdf2:<0.261630:*:*:*:*:*:*:*

References