MEDIUM SEVERITYCONFIRMED
pbkdf2_sha256.hash("") succeeds — no minimum password length
Package
passlib
Version
1.7.4
Verified
2026-03-28
Description
passlib's `pbkdf2_sha256` hasher accepts and successfully verifies an empty string password. No `min_length` parameter exists in the passlib API, and the library provides no mechanism to enforce a minimum password length at the hashing layer.
Reproduction
from passlib.hash import pbkdf2_sha256
h = pbkdf2_sha256.hash("")
pbkdf2_sha256.verify("", h) # True — no error