Sjoerd Langkemper has proposed PASSWORD_BCRYPT_SHA256 as a new algorithm for password_hash and password_verify. The mode would process the password with HMAC SHA256 before passing the result to bcrypt. This addresses two limitations of current bcrypt handling: problems with null bytes and the 72-byte input limit, because bcrypt hashes only the first 72 bytes.

The RFC is available at https://wiki.php.net/rfc/bcrypt_sha256, with an implementation proposed in PHP source pull request 24073 at https://github.com/php/php-src/pull/24073. Langkemper previously considered an RFC that would make passwords longer than 72 bytes produce an error. That approach faced criticism because of its backward incompatibility, so he is not pursuing it for now. The new algorithm is presented as a less disruptive way to address the same underlying problem. The earlier proposal is documented at https://wiki.php.net/rfc/bcrypt_max_password_length.