Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94206— Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds

Quick assessment

Affected
danielberkompas cloak_ecto
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

danielberkompas/cloak_ecto 和 danielberkompas/cloak 中存在“使用计算强度不足的密码哈希”漏洞。持有哈希值和配置密钥的攻击者可以比配置预期更快地对低熵明文执行暴力破解。 Cloak.Ecto.PBKDF2(在 Ecto 代码迁移至 cloak_ecto 之前位于 cloak/fields/PBKDF2)向字段模块注入的 回调函数中,调用了 ,并将配置项 错误地放在迭代次数(iteration-count)参数位置。虽然 配置项经过了有效性验证,但实际并未被使用。以 c

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1552 · Unsecured Credentials
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94206

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds
Source: CVE Program / CVE List V5
Vulnerability Description
Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2 (Cloak.Fields.PBKDF2 in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls :pbkdf2.pbkdf2/4 with config[:size] in the iteration-count position. The :iterations setting is validated but never used. With the cloak_ecto defaults (iterations: 600_000, size: 32) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured. This issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用具有不充分计算复杂性的口令哈希
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
danielberkompas cloak_ecto 1.0.0-alpha.0 ~ * cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*
danielberkompas cloak_ecto a8fa1642b02f1c445a1ee8794c9095eb0921f8f3 ~ * cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*
danielberkompas cloak 0.7.0 ~ 1.0.0-alpha.0 cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*
danielberkompas cloak 8699e6417a162c39d9f0ef63511bd23d3f38d1d2 ~ 681c9702b7cd9afe0e5a840751ab009f550c69a9 cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-94206

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94206

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-94206 (1)

News Coverage for CVE-2026-94206 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-94206

No comments yet


Leave a comment