[spark-test] Fix VerifyPassword Argon2 DoS #11

Open
opened 2026-03-23 14:13:19 +00:00 by Virgil · 0 comments
Member

VerifyPassword accepts attacker-controlled Argon2 params. Cap time/memory/parallelism.

VerifyPassword accepts attacker-controlled Argon2 params. Cap time/memory/parallelism.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

-

Dependencies

No dependencies set.

Reference: core/go-crypt#11
No description provided.