HIGH SEVERITYCONFIRMED

Complete incompatibility with bcrypt 4.x/5.x — bcrypt.hash() broken

Package
passlib
Version
1.7.4
Verified
2026-03-28

Description

passlib 1.7.4 is completely broken with bcrypt 5.0.0. Failure chain: (1) passlib reads `bcrypt.__about__.__version__` — `AttributeError` (removed in bcrypt 4.0); (2) passlib's `detect_wrap_bug()` passes a 255-byte probe to `bcrypt.hashpw()`; (3) bcrypt 5.0.0 enforces the 72-byte limit strictly, raising `ValueError`; (4) the `ValueError` propagates uncaught. All passlib bcrypt operations fail.

Reproduction

from passlib.hash import bcrypt as passlib_bcrypt
passlib_bcrypt.hash('password')
# ValueError: password cannot be longer than 72 bytes, truncate manually if necessary
← All bugsScan your code →