MEDIUM SEVERITYCONFIRMED

pbkdf2_sha256.hash("") succeeds — no minimum password length

Package
passlib
Version
1.7.4
Verified
2026-03-28

Description

passlib's `pbkdf2_sha256` hasher accepts and successfully verifies an empty string password. No `min_length` parameter exists in the passlib API, and the library provides no mechanism to enforce a minimum password length at the hashing layer.

Reproduction

from passlib.hash import pbkdf2_sha256
h = pbkdf2_sha256.hash("")
pbkdf2_sha256.verify("", h)  # True — no error
← All bugsScan your code →