PT-2026-106766 · Pyload · Pyload
CVE-2026-105804
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
5.6
Medium
| Vector | AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Payload versions 3.0.0 through 3.89.9
Payload versions 4.0.0-canary.0 through 4.0.0-canary.33
Description
The software uses a lower-than-recommended PBKDF2 work factor for password hashing. PBKDF2 (Password-Based Key Derivation Function 2) is a method used to reduce the vulnerability of passwords to brute-force attacks by applying a hash function repeatedly. Using a lower work factor reduces the computational effort required for an attacker to test recovered password hashes.
Recommendations
Update Payload versions 3.0.0 through 3.89.9 to version 3.90.0 or later.
Update Payload versions 4.0.0-canary.0 through 4.0.0-canary.33 to version 4.0.0-canary.34 or later.
Protect database copies and backups from unauthorized access.
Require the use of strong, unique passwords.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyload