{"id":"CVE-2020-7689","aliases":["GHSA-5wg4-74h6-q47v","SNYK-JS-BCRYPT-572911"],"url":"https://o3.security/vulnerability/CVE-2020-7689","summary":"Integer Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algorithm in bcrypt","details":"Data is truncated wrong when its length is greater than 255 bytes.","published":"2020-07-01T14:15:14.623Z","modified":"2026-07-09T12:32:52.968304Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"bcrypt","fixedVersion":"5.0.0"}],"fix":{"url":"https://github.com/kelektiv/node.bcrypt.js/pull/806","label":"kelektiv/node.bcrypt.js#806"},"references":[{"type":"ADVISORY","url":"https://github.com/kelektiv/node.bcrypt.js/issues/776"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-BCRYPT-572911"},{"type":"FIX","url":"https://github.com/kelektiv/node.bcrypt.js/pull/806"},{"type":"FIX","url":"https://github.com/kelektiv/node.bcrypt.js/pull/807"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:32:52.968304Z"}}