The Daily Commit · Section Edition Front Page PHP AI Dev EN DE FR ES

The Php Times

RFC Watch — Ecosystem

PHP RFC would reject oversized bcrypt passwords


Sjoerd Langkemper has proposed the PHP RFC bcrypt_max_password_length.

PHP INTERNALS ([RFC]/[VOTE]), September 29, 2026 curated by Sönke

It would make password_hash() throw ValueError when bcrypt receives input longer than 72 bytes. PHP currently truncates longer input silently, hashing only the first 72 bytes. The change targets severe security vulnerabilities, especially in applications that hash data beyond a user’s password.

Sjoerd Langkemper has drafted the PHP RFC bcrypt_max_password_length. It proposes that password_hash() throw ValueError when bcrypt receives a password longer than 72 bytes.

PHP currently truncates longer input without warning and hashes only the first 72 bytes. The proposal aims to prevent severe security vulnerabilities caused by this behavior. It would primarily affect applications that pass data other than the user’s password to password_hash().

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

← Ecosystem — Page B1

"All the Code That's Fit to Ship" · The Daily Commit · Screen edition · Imprint · Privacy Policy