CUPP Concatenation Threshold: How to Adjust It for Large Wordlists

The CUPP concatenation threshold defaults to 200 words to prevent memory exhaustion from quadratic expansion, and you can adjust this limit by modifying the threshold value in cupp.cfg before running the tool with the -w flag.

CUPP (Common User Passwords Profiler) from the Mebus/cupp repository generates password candidates by combining entries from supplied wordlists. The concatenation threshold serves as a critical safeguard that limits how many words can be pairwise concatenated, protecting your system from runaway memory usage when processing large dictionaries.

What Is the CUPP Concatenation Threshold?

The concatenation threshold is a memory protection mechanism that controls the maximum wordlist size eligible for pairwise concatenation. When you invoke CUPP with the -w (improve dictionary) option, the tool attempts to generate new password candidates by joining every word in the list with every other word.

This operation produces N × N combinations. With the default threshold of 200, CUPP generates approximately 40,000 concatenated strings. Without this limit, a 5,000-word list would create roughly 25 million combinations, potentially crashing the process due to RAM exhaustion.

Where the Threshold Is Configured and Enforced

Configuration in cupp.cfg

The threshold value is defined in the cupp.cfg configuration file at the repository root. Under the Threshold section, the threshold parameter sets the hard limit:

[Threshold]
threshold=200

You can typically locate this setting around line 62 in the configuration file.

Runtime Validation in cupp.py

During execution, cupp.py reads this value into CONFIG["global"]["threshold"] around line 71. The actual enforcement occurs near line 208, where the script compares your wordlist length against the configured threshold before proceeding with concatenation.

If the wordlist exceeds the limit, CUPP displays a warning and prompts for confirmation:

[-] Maximum number of words for concatenation is 200
[-] Check configuration file for increasing this number.

Do you want to concatenate all words from wordlist? Y/[N]:

How to Adjust the Concatenation Threshold for Large Wordlists

To process wordlists larger than 200 entries, modify the configuration and confirm the operation. Follow these steps to safely increase the limit:

  1. Edit the configuration file

    Open cupp.cfg and locate the threshold entry. Change the value to match your system's memory capacity:

    threshold=1000
  2. Execute CUPP with the improve dictionary flag

    Run the tool against your large wordlist:

    python3 cupp.py -w large_wordlist.txt
  3. Confirm the operation if prompted

    If your list still exceeds the new threshold, type y when prompted to proceed. The warning is informational and allows you to abort if the combination count risks system stability.

Memory Impact and Scaling Considerations

Understanding the quadratic growth helps you set appropriate thresholds. The relationship between wordlist size and memory usage follows this pattern:

  • 200 words: ~40,000 concatenations (default threshold)
  • 1,000 words: ~1,000,000 concatenations
  • 5,000 words: ~25,000,000 concatenations

When adjusting the threshold in cupp.cfg for substantial wordlists, ensure your system has sufficient RAM to handle the resulting combination set. For example, setting threshold=6000 allows processing of 5,000-entry lists but requires adequate memory to store millions of generated strings.

Summary

  • The concatenation threshold in CUPP defaults to 200 words to prevent memory exhaustion from quadratic growth.
  • The limit is configured in cupp.cfg and enforced at runtime in cupp.py when using the -w flag.
  • Adjust the threshold by editing cupp.cfg and setting a higher value appropriate for your system's RAM.
  • Always confirm the operation when warned, as the N × N concatenation can generate millions of strings from large wordlists.

Frequently Asked Questions

What happens if I set the concatenation threshold too high in CUPP?

Setting the threshold too high risks memory exhaustion and process termination. When processing a 5,000-word list, CUPP generates approximately 25 million concatenated strings. If your system lacks sufficient RAM to store these combinations, the Python process may crash or become unresponsive during dictionary generation.

Can I bypass the concatenation threshold without editing cupp.cfg?

Yes, you can temporarily bypass the threshold by pressing y when CUPP prompts you to confirm concatenation after displaying the warning. However, this only works for that specific execution and does not change the underlying configuration in cupp.cfg. You must still confirm the operation each time you exceed the limit.

Where exactly does CUPP check the wordlist size against the threshold?

CUPP performs the threshold check in cupp.py around line 208 during the dictionary improvement workflow. The script first reads the configuration value from CONFIG["global"]["threshold"] (set around line 71), then compares your wordlist length against this value before executing the concatenation logic.

Why does CUPP use a default concatenation threshold of 200?

The default value of 200 prevents accidental resource exhaustion on standard systems. At 200 words, CUPP generates approximately 40,000 combinations, which is manageable on most machines. This safety limit ensures users must consciously decide to consume additional memory when processing larger wordlists.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →