bcrypt
bcrypt() is a sophisticated and secure hash algorithm designed by The OpenBSD project for hashing passwords. The bcrypt Ruby gem provides a simple wrapper for safely handling passwords.
Activity
- Latest release
- 5mo ago
- Total releases
- 19
- Cadence
- ~4 months
- Last 12 months
- 2
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Feb 21, 2014
| Version | Released | |
|---|---|---|
3.1.22
patch
| ||
3.1.21
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.20
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.19
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.18
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.17
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.16
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.14
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.15
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.13
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.12
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.12.rc1
pre
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.11
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.10
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.9
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.8
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.7
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.6
patch
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev | ||
3.1.3
initial
1 CVE
CVE-2026-33306
GHSA-f27w-vcwj-c954
Mar 19, 2026
bcrypt-ruby has an Integer Overflow that Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
Medium
Local
High
None
None
ImpactAn integer overflow in the Java BCrypt implementation for JRuby can cause zero iterations in the strengthening loop. Impacted applications must be setting the cost to 31 to see this happen. The JRuby implementation of bcrypt-ruby ( The resulting hash looks valid ( PatchesThis problem has been fixed in version 3.1.22 WorkaroundsSet the cost to something less than 31. Affected versions
3.1.10
3.1.11
3.1.12
3.1.12.rc1
3.1.13
3.1.14
3.1.15
3.1.16
3.1.17
3.1.18
3.1.19
3.1.20
+ 6 more Show less
3.1.21
3.1.3
3.1.6
3.1.7
3.1.8
3.1.9
Fixed in
3.1.22
References
Updated Mar 25, 2026 · Source: OSV.dev |