Sjoerd Langkemper has drafted the PHP RFC bcrypt_max_password_length. It proposes that password_hash() throw ValueError when bcrypt receives a password longer than 72 bytes.

PHP currently truncates longer input without warning and hashes only the first 72 bytes. The proposal aims to prevent severe security vulnerabilities caused by this behavior. It would primarily affect applications that pass data other than the user’s password to password_hash().