CVE-2016-20013: SHA256CRYPT Project SHA256CRYPT
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
Affected products
- SHA256CRYPT Project SHA256CRYPT: up to and including 0.6
- SHA512CRYPT Project SHA512CRYPT: up to and including 0.6
Published 2022-02-19. Last modified 2026-06-17.