€0.00 — free as in speechtonight's forecast: clear skies over production Cache: warm · Deploys: fair, 0% rollbacks expectedset by moonlight, shipped before dawn · deploy freely Page A2

❦The Daily Commit❦ ☾The Nightly Build☽

Dev news, typeset daily — PHP · AI · The Wider Stack

The developer's evening paper — PHP · AI · The Wider Stack

Wednesday, September 30, 2026 Vol. I — No. 679 · Morning editionLate edition EN DE FR ES

PHP · RFC Watch

PHP RFC would reject oversized bcrypt passwords

Sjoerd Langkemper has proposed the PHP RFC bcrypt_max_password_length.

curated by Sönke

It would make password_hash() throw ValueError when bcrypt receives input longer than 72 bytes. PHP currently truncates longer input silently, hashing only the first 72 bytes. The change targets severe security vulnerabilities, especially in applications that hash data beyond a user’s password.

Sjoerd Langkemper has drafted the PHP RFC bcrypt_max_password_length. It proposes that password_hash() throw ValueError when bcrypt receives a password longer than 72 bytes.

PHP currently truncates longer input without warning and hashes only the first 72 bytes. The proposal aims to prevent severe security vulnerabilities caused by this behavior. It would primarily affect applications that pass data other than the user’s password to password_hash().

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← The Daily CommitThe Nightly Build — Page A1