Payload: Password hashes use insufficient PBKDF2 iterations
Moderate severity
GitHub Reviewed
Published
Sep 29, 2026
in
payloadcms/payload
•
Updated Oct 6, 2026
Package
Affected versions
>= 3.0.0, < 3.90.0
>= 4.0.0-canary.0, < 4.0.0-canary.34
Patched versions
3.90.0
4.0.0-canary.34
Description
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Impact
The password-hashing configuration used a lower work factor than what is recommended.
Patches
Payload now uses stronger password-hashing parameters and transparently upgrades older hashes following a successful login.
Users should upgrade Payload packages to
>= 3.90.0or>= 4.0.0-canary.34.Workarounds
Upgrading is recommended. Until you can upgrade, protect database copies and backups from unauthorized access and require strong, unique passwords.
References