Vulnerability GHSA-q6mq-ch85-c8mm

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
October 06, 2026 at 03:38 PM UTC
Payload: Password hashes use insufficient PBKDF2 iterations
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
3.0.0 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload: Password hashes use insufficient PBKDF2 iterations

Details

Impact

The password-hashing configuration used a lower work factor than what is recommended.

Patches

Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Workarounds

Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 03:38 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC