{"affected":[{"package":{"ecosystem":"Hex","name":"cloak_ecto","purl":"pkg:hex/cloak_ecto"},"ranges":[{"events":[{"introduced":"1.0.0-alpha.0"}],"type":"SEMVER"}],"versions":["1.0.0-alpha.0","1.0.0","1.0.1","1.0.2","1.1.0","1.1.1","1.2.0","1.3.0"]},{"package":{"ecosystem":"Hex","name":"cloak","purl":"pkg:hex/cloak"},"ranges":[{"events":[{"introduced":"0.7.0"},{"fixed":"1.0.0-alpha.0"}],"type":"SEMVER"}],"versions":["0.7.0","0.8.0","0.9.0","0.9.1","0.9.2"]},{"ranges":[{"events":[{"introduced":"a8fa1642b02f1c445a1ee8794c9095eb0921f8f3"}],"repo":"https://github.com/danielberkompas/cloak_ecto","type":"GIT"}]},{"ranges":[{"events":[{"introduced":"8699e6417a162c39d9f0ef63511bd23d3f38d1d2"},{"fixed":"681c9702b7cd9afe0e5a840751ab009f550c69a9"}],"repo":"https://github.com/danielberkompas/cloak","type":"GIT"}]}],"aliases":["CVE-2026-94206"],"credits":[{"name":"Peter Ullrich","type":"FINDER"},{"name":"Peter Ullrich","type":"REPORTER"},{"name":"Jonatan Männchen / EEF","type":"COORDINATOR"}],"database_specific":{"capec_ids":["CAPEC-55"],"cpe_ids":["cpe:2.3:a:danielberkompas:cloak_ecto:*:*:*:*:*:*:*:*","cpe:2.3:a:danielberkompas:cloak:*:*:*:*:*:*:*:*"],"cwe_ids":["CWE-916"]},"details":"## Summary\n\nUse of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured.\n\nThe `dump/1` callback that `Cloak.Ecto.PBKDF2` (`Cloak.Fields.PBKDF2` in cloak before the Ecto code moved to cloak_ecto) injects into a field module calls `:pbkdf2.pbkdf2/4` with `config[:size]` in the iteration-count position. The `:iterations` setting is validated but never used. With the cloak_ecto defaults (`iterations: 600_000`, `size: 32`) each hash runs 32 PBKDF2 rounds instead of 600,000, so offline guessing of values such as email addresses costs about 18,750 times less than configured.\n\nThis issue affects cloak_ecto: from 1.0.0-alpha.0 onward; cloak: from 0.7.0 before 1.0.0-alpha.0.\n\n## Proof of concept\n\n1. Define a field module with `use Cloak.Ecto.PBKDF2` and configure only a `:secret`, so that the defaults `iterations: 600_000` and `size: 32` apply.\n2. Call `dump/1` on a value.\n3. Compare the result with `:pbkdf2.pbkdf2({:hmac, :sha256}, value, secret, 32)` and with the same call at 600,000 rounds. It matches the 32-round hash, not the 600,000-round hash, and returns in microseconds instead of about one second.\n\n## Impact\n\nAn attacker who obtains a database dump and the PBKDF2 secret can recover hashed values with low entropy, such as email addresses, by offline guessing at a cost far below what the configuration promises.\n\n## Workarounds\n\nOverride `dump/1` in the field module that uses `Cloak.Ecto.PBKDF2`, so that it calls `:pbkdf2.pbkdf2/5` with the configured `:iterations` and `:size`. Then recompute all stored hashes, because the existing values no longer match.","id":"EEF-CVE-2026-94206","modified":"2026-10-06T08:38:05.415563Z","published":"2026-10-06T08:38:04.584Z","references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-94206.html"},{"type":"WEB","url":"https://github.com/danielberkompas/cloak_ecto/commit/a8fa1642b02f1c445a1ee8794c9095eb0921f8f3"},{"type":"WEB","url":"https://github.com/danielberkompas/cloak/commit/8699e6417a162c39d9f0ef63511bd23d3f38d1d2"},{"type":"FIX","url":"https://github.com/danielberkompas/cloak/commit/681c9702b7cd9afe0e5a840751ab009f550c69a9"},{"type":"PACKAGE","url":"https://hex.pm/packages/cloak_ecto"},{"type":"PACKAGE","url":"https://hex.pm/packages/cloak"}],"related":[],"schema_version":"1.7.3","severity":[{"score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","type":"CVSS_V4"}],"summary":"Cloak PBKDF2 field ignores the configured iteration count and runs only :size rounds","upstream":[]}