Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

OverflowError: math range error

Open
#13 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
python
Domain
security

Research direction

Start in zxcvbn/scoring.py at entropy_to_crack_time, using the traceback and the long-password reproduction as the entry point. Check the existing tests for scoring and add coverage for very long inputs; done means password_strength handles that input without raising OverflowError.

Written by the indexing model from the issue text.

Description

I started receiving error 500 emails from my Django project, revealing that someone has been trying to input extremely long passwords. I can easily reproduce this with zxcvbn 1.0:

from zxcvbn import password_strength

>>> password = "this is a test"
>>> password_strength(password)

[normal results]

>>> password = "Heavy flooding over eastern Japan washed away houses and forced residents to their rooftops, desperate for rescue by military helicopters.  The raging brown floodwaters spawned from Typhoon Etau, which has dumped 60 centimeters (2 feet) of rain over some areas since Monday.  Combine that with several weeks of near-daily rainfall, and Ibaraki and Tochigi prefectures are now deluged and unrecognizable."

>>> password_strength(password)                                                                                                                             Traceback (most recent call last):
  File "<console>", line 1, in <module>
  File "/Users/me/Sites/virtualenvs/foo/lib/python2.7/site-packages/zxcvbn/main.py", line 10, in password_strength
    result = minimum_entropy_match_sequence(password, matches)
  File "/Users/me/Sites/virtualenvs/foo/lib/python2.7/site-packages/zxcvbn/scoring.py", line 109, in minimum_entropy_match_sequence
    crack_time = entropy_to_crack_time(min_entropy)
  File "/Users/me/Sites/virtualenvs/foo/lib/python2.7/site-packages/zxcvbn/scoring.py", line 150, in entropy_to_crack_time
    return (0.5 * math.pow(2, entropy)) * SECONDS_PER_GUESS # average, not total
OverflowError: math range error
Dominant language
HTML
Stars
259
Forks
56
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dropbox/python-zxcvbn

All issues in dropbox/python-zxcvbn

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.