sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-20013.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "0.6" } ] }, { "events": [ { "introduced": "0" }, { "last_affected": "0.6" } ] } ]