Skip to content

Feat/unsafe prehash#661

Open
ErwanRaulo wants to merge 2 commits into
masterfrom
feat/unsafe-prehash
Open

Feat/unsafe prehash#661
ErwanRaulo wants to merge 2 commits into
masterfrom
feat/unsafe-prehash

Conversation

@ErwanRaulo

@ErwanRaulo ErwanRaulo commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Adds an optional unsafe-prehash probe to detect insecure usage of null byte enconding prehash, commonly used later on with bcrypt

Partially complete #506 for bcrypt (prehash is a subset)

@ErwanRaulo ErwanRaulo marked this pull request as ready for review June 29, 2026 14:35
@ErwanRaulo ErwanRaulo requested a review from a team as a code owner June 29, 2026 14:35
@ErwanRaulo ErwanRaulo force-pushed the feat/unsafe-prehash branch from 445b055 to 83d4a8f Compare June 29, 2026 14:35
@changeset-bot

changeset-bot Bot commented Jun 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 20a6969

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@nodesecure/js-x-ray Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@ErwanRaulo ErwanRaulo force-pushed the feat/unsafe-prehash branch from 83d4a8f to 20a6969 Compare June 30, 2026 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant