Vulnerability GHSA-q6mq-ch85-c8mm
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 06, 2026 at 03:38 PM UTC
Payload: Password hashes use insufficient PBKDF2 iterations
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
Summary
Payload: Password hashes use insufficient PBKDF2 iterations
Details
Impact
The password-hashing configuration used a lower work factor than what is recommended.
Patches
Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Workarounds
Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
1 hour ago
Payload didn't enforce field-level password update restrictions
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-fx49-4h83-wjv9
High Risk
1 hour ago
Payload: ReDoS in Multipart Content-Type Validation
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-2g7p-5934-q4w7
High Risk
1 hour ago
Payload vulnerable to API key disclosure through ordinary document reads
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-238x-w2j9-gwwr
Medium Risk
1 hour ago
Payload relationship-query authorization bypass
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-7c34-32v3-j575
High Risk
1 hour ago
Payload: Token refresh and password reset responses may expose restricted user fields
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33 GHSA-xgv3-crq2-6f69
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 03:38 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC