This is an automated email from the ASF dual-hosted git repository.

garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-codec.git


The following commit(s) were added to refs/heads/master by this push:
     new a5c00769 [CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
a5c00769 is described below

commit a5c007691dceff744dffca94fc6ce714a5b68622
Author: Efe <[email protected]>
AuthorDate: Sat Sep 26 23:25:19 2026 +0300

    [CODEC-245] Reject malformed Sha2Crypt salt syntax (#445)
    
    * [CODEC-245] Reject malformed Sha2Crypt salt syntax
    
    Require the optional rounds clause and salt suffix to use the documented 
separators and character set. Add regression coverage for malformed rounds text 
and non-ASCII salt input.
    
    * Fix SALT_PATTERN regex to match end of string
    
    Co-authored-by: Copilot Autofix powered by AI 
<[email protected]>
    
    * Update test for sha512Crypt with valid input
    
    Co-authored-by: Copilot Autofix powered by AI 
<[email protected]>
    
    ---------
    
    Co-authored-by: Gary Gregory <[email protected]>
    Co-authored-by: Copilot Autofix powered by AI 
<[email protected]>
---
 src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java       | 2 +-
 src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java | 4 ++++
 2 files changed, 5 insertions(+), 1 deletion(-)

diff --git a/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java 
b/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
index 5325ee30..62887eb0 100644
--- a/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
+++ b/src/main/java/org/apache/commons/codec/digest/Sha2Crypt.java
@@ -87,7 +87,7 @@ public class Sha2Crypt {
 
     /** The pattern to match valid salt values. */
     private static final Pattern SALT_PATTERN = Pattern
-            
.compile("^\\$([56])\\$(rounds=(\\d+)\\$)?([\\.\\/a-zA-Z0-9]{1,16}).*");
+            
.compile("^\\$([56])\\$(rounds=(\\d+)\\$)?([\\.\\/a-zA-Z0-9]{1,16})[\\.\\/a-zA-Z0-9]*(?:\\$.*)?\\z");
 
     /**
      * Finds the first non-zero digit, retaining one zero for an all-zero 
value.
diff --git a/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java 
b/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
index f1eefd2a..eaf2605c 100644
--- a/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
+++ b/src/test/java/org/apache/commons/codec/digest/Sha512CryptTest.java
@@ -50,6 +50,10 @@ class Sha512CryptTest {
     @Test
     void testSha2CryptWrongSalt() {
         assertThrows(IllegalArgumentException.class, () -> 
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8), "xx"));
+        assertThrows(IllegalArgumentException.class,
+                () -> 
Sha2Crypt.sha256Crypt("secret".getBytes(StandardCharsets.UTF_8), 
"$5$notrounds=1000$asdfasdf"));
+        assertThrows(IllegalArgumentException.class,
+                () -> 
Sha2Crypt.sha512Crypt("secret".getBytes(StandardCharsets.UTF_8), 
"$6$rounds=1000$abcäöüäöü"));
     }
 
     @Test

Reply via email to