# Concatenation Threshold in CUPP: How to Control Memory Usage When Building Password Dictionaries

> Learn how the concatenation threshold in CUPP controls memory usage by limiting wordlist combinations. Prevent RAM exhaustion and optimize dictionary generation.

- Repository: [Mebus/cupp](https://github.com/Mebus/cupp)
- Tags: performance
- Published: 2026-07-01

---

**The concatenation threshold in CUPP is a memory safeguard configured in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) that limits wordlist concatenation to 200 words by default, preventing RAM exhaustion by blocking the generation of up to 40,000 combined strings unless explicitly confirmed.**

CUPP (Common User Passwords Profiler) generates custom password dictionaries by mutating personal information and combining wordlist entries. When using the `-w` option to improve wordlists, the tool attempts to concatenate every word with every other word, an operation that can exponentially increase memory usage. The **concatenation threshold** acts as a critical guardrail to prevent system crashes on low-memory machines.

## Where the Concatenation Threshold Is Defined

The threshold value originates in the configuration file **[`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg)**. By default, the `[nums]` section sets this limit to **200**:

```ini
[nums]
from=0
to=100
threshold=200

```

*Source:* [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) line 62

At runtime, CUPP loads this value into a global configuration dictionary in **[`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)**:

```python
CONFIG["global"] = {
    ...
    "threshold": config.getint("nums", "threshold"),
}

```

*Source:* [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) line 71

This makes the threshold available throughout the application as `CONFIG["global"]["threshold"]`.

## How the Threshold Controls Memory Usage

When you enable wordlist concatenation with the `-w` flag, CUPP checks the size of the loaded wordlist against the threshold before executing the memory-intensive operation:

```python
if conts == "y" and len(listic) > CONFIG["global"]["threshold"]:
    print("\n[-] Maximum number of words for concatenation is "
          + str(CONFIG["global"]["threshold"]))
    print("[-] Check configuration file for increasing this number.\n")
    conts = input("> Do you want to concatenate all words from wordlist? Y/[N]: ").lower()

```

*Source:* [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) lines 208-215

**Memory impact explanation:**
- Concatenating *n* words creates up to **n × n** new string combinations
- With the default threshold of 200, this generates up to 40,000 combined entries
- The entire list resides in memory before being flushed to disk, meaning a 500-word list could attempt to create 250,000 strings, potentially exhausting available RAM on constrained systems

The threshold acts as a circuit breaker: if the wordlist exceeds the configured limit, CUPP warns the user and requires explicit confirmation before proceeding, or allows the user to abort the concatenation step entirely.

## Modifying the Threshold Configuration

You can adjust the trade-off between dictionary comprehensiveness and memory consumption by editing [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg).

**To increase the limit**, modify the value in the `[nums]` section:

```ini
[nums]
threshold=500

```

This allows concatenation of larger wordlists without interruption, but be aware that a 500-word list will generate up to 250,000 combinations, significantly increasing memory pressure.

**To disable concatenation entirely**, set the threshold to `0` or answer `n` when prompted. This skips the concatenation step and keeps memory usage minimal.

## Practical Code Examples

### Default Behavior (Threshold = 200)

With a wordlist containing 250 words:

```bash
python3 cupp.py -w wordlist.txt

```

Output:

```

[-] Maximum number of words for concatenation is 200
[-] Check configuration file for increasing this number.
> Do you want to concatenate all words from wordlist? Y/[N]:

```

CUPP blocks automatic concatenation of the 250-word list, which would have created 62,500 combinations.

### High-Memory Configuration

Edit [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) to raise the limit:

```ini
threshold=1000

```

Now CUPP will allow concatenation of wordlists up to 1,000 words without warning, but will allocate memory for up to 1,000,000 string combinations during execution.

### Verification Check

To verify your current threshold setting:

```bash
grep "threshold" cupp.cfg

```

This outputs the configured value, confirming the memory boundary that will be enforced during wordlist generation.

## Summary

- The **concatenation threshold** is defined in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) under the `[nums]` section and defaults to **200**
- CUPP loads this value at startup in [`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py) (line 71) and enforces it before concatenating words (lines 208-215)
- The threshold prevents memory exhaustion by limiting the *n × n* combinations generated when concatenating wordlists
- Users can adjust the threshold to balance between dictionary size and available RAM, or set it to `0` to disable concatenation entirely

## Frequently Asked Questions

### What happens if I set the concatenation threshold to 0?

Setting `threshold=0` in [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) effectively disables the concatenation safeguard. However, since CUPP checks if the wordlist length exceeds the threshold, a value of 0 means any wordlist with 1 or more words will trigger the warning prompt. To completely skip concatenation, answer `n` when prompted or avoid using the `-w` flag.

### How much memory does wordlist concatenation consume?

Memory consumption scales quadratically with wordlist size. A wordlist of *n* words creates up to **n²** concatenated strings. For example, 200 words generate 40,000 new strings, while 1,000 words generate 1,000,000 strings. Each string resides in memory until written to disk, meaning a 1,000-word concatenation could consume several hundred megabytes of RAM depending on average word length.

### Can I disable the concatenation warning without changing the config file?

No, the threshold check is mandatory in the source code. The only way to bypass the warning for large wordlists is to answer `Y` when prompted, or to edit [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) to raise the threshold value before running CUPP. There is no command-line flag to override this memory protection mechanism.

### Where is the concatenation logic implemented in the source code?

The concatenation logic and threshold check are implemented in **[`cupp.py`](https://github.com/Mebus/cupp/blob/main/cupp.py)** between lines 208-215. The configuration is read from [`cupp.cfg`](https://github.com/Mebus/cupp/blob/main/cupp.cfg) and stored in the global `CONFIG` dictionary at line 71. The actual string concatenation occurs after the threshold check passes, where CUPP combines every word in the list with every other word to generate permutations.