This is an automated email from the ASF dual-hosted git repository.
garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-codec.git
The following commit(s) were added to refs/heads/master by this push:
new a5c00769 [CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
a5c00769 is described below
commit a5c007691dceff744dffca94fc6ce714a5b68622
Author: Efe <[email protected]>
AuthorDate: Sat Sep 26 23:25:19 2026 +0300
[CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
* [CODEC-245] Reject malformed Sha2Crypt salt syntax
Require the optional rounds clause and salt suffix to use the documented
separators and character set. Add regression coverage for malformed rounds text
and non-ASCII salt input.
* Fix SALT_PATTERN regex to match end of string
Co-authored-by: Copilot Autofix powered by AI
<[email protected]>
* Update test for sha512Crypt with valid input
Co-authored-by: Copilot Autofix powered by AI
<[email protected]>
---------
Co-authored-by: Gary Gregory <[email protected]>
Co-authored-by: Copilot Autofix powered by AI
<[email protected]>
---
src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java | 2 +-
src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java | 4 ++++
2 files changed, 5 insertions(+), 1 deletion(-)
diff --git a/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
b/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
index 5325ee30..62887eb0 100644
--- a/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
+++ b/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
@@ -87,7 +87,7 @@ public class Sha2Crypt {
/** The pattern to match valid salt values. */
private static final Pattern SALT_PATTERN = Pattern
-
.compile("^\\$([56])\\$(rounds=(\\d+)\\$)?([\\.\\/a-zA-Z0-9]{1,16}).*");
+
.compile("^\\$([56])\\$(rounds=(\\d+)\\$)?([\\.\\/a-zA-Z0-9]{1,16})[\\.\\/a-zA-Z0-9]*(?:\\$.*)?\\z");
/**
* Finds the first non-zero digit, retaining one zero for an all-zero
value.
diff --git a/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
b/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
index f1eefd2a..eaf2605c 100644
--- a/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
+++ b/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
@@ -50,6 +50,10 @@ class Sha512CryptTest {
@Test
void testSha2CryptWrongSalt() {
assertThrows(IllegalArgumentException.class, () ->
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8), "xx"));
+ assertThrows(IllegalArgumentException.class,
+ () ->
Sha2Crypt.sha256Crypt("secret".getBytes(StandardCharsets.UTF_8),
"$5$notrounds=1000$asdfasdf"));
+ assertThrows(IllegalArgumentException.class,
+ () ->
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8),
"$6$rounds=1000$abcäöüäöü"));
}
@Test