Concatenation Threshold in CUPP: How to Control Memory Usage When Building Password Dictionaries

The concatenation threshold in CUPP is a memory safeguard configured in cupp.cfg that limits wordlist concatenation to 200 words by default, preventing RAM exhaustion by blocking the generation of up to 40,000 combined strings unless explicitly confirmed.

CUPP (Common User Passwords Profiler) generates custom password dictionaries by mutating personal information and combining wordlist entries. When using the -w option to improve wordlists, the tool attempts to concatenate every word with every other word, an operation that can exponentially increase memory usage. The concatenation threshold acts as a critical guardrail to prevent system crashes on low-memory machines.

Where the Concatenation Threshold Is Defined

The threshold value originates in the configuration file cupp.cfg. By default, the [nums] section sets this limit to 200:

[nums]
from=0
to=100
threshold=200

Source: cupp.cfg line 62

At runtime, CUPP loads this value into a global configuration dictionary in cupp.py:

CONFIG["global"] = {
    ...
    "threshold": config.getint("nums", "threshold"),
}

Source: cupp.py line 71

This makes the threshold available throughout the application as CONFIG["global"]["threshold"].

How the Threshold Controls Memory Usage

When you enable wordlist concatenation with the -w flag, CUPP checks the size of the loaded wordlist against the threshold before executing the memory-intensive operation:

if conts == "y" and len(listic) > CONFIG["global"]["threshold"]:
    print("\n[-] Maximum number of words for concatenation is "
          + str(CONFIG["global"]["threshold"]))
    print("[-] Check configuration file for increasing this number.\n")
    conts = input("> Do you want to concatenate all words from wordlist? Y/[N]: ").lower()

Source: cupp.py lines 208-215

Memory impact explanation:

  • Concatenating n words creates up to n × n new string combinations
  • With the default threshold of 200, this generates up to 40,000 combined entries
  • The entire list resides in memory before being flushed to disk, meaning a 500-word list could attempt to create 250,000 strings, potentially exhausting available RAM on constrained systems

The threshold acts as a circuit breaker: if the wordlist exceeds the configured limit, CUPP warns the user and requires explicit confirmation before proceeding, or allows the user to abort the concatenation step entirely.

Modifying the Threshold Configuration

You can adjust the trade-off between dictionary comprehensiveness and memory consumption by editing cupp.cfg.

To increase the limit, modify the value in the [nums] section:

[nums]
threshold=500

This allows concatenation of larger wordlists without interruption, but be aware that a 500-word list will generate up to 250,000 combinations, significantly increasing memory pressure.

To disable concatenation entirely, set the threshold to 0 or answer n when prompted. This skips the concatenation step and keeps memory usage minimal.

Practical Code Examples

Default Behavior (Threshold = 200)

With a wordlist containing 250 words:

python3 cupp.py -w wordlist.txt

Output:


[-] Maximum number of words for concatenation is 200
[-] Check configuration file for increasing this number.
> Do you want to concatenate all words from wordlist? Y/[N]:

CUPP blocks automatic concatenation of the 250-word list, which would have created 62,500 combinations.

High-Memory Configuration

Edit cupp.cfg to raise the limit:

threshold=1000

Now CUPP will allow concatenation of wordlists up to 1,000 words without warning, but will allocate memory for up to 1,000,000 string combinations during execution.

Verification Check

To verify your current threshold setting:

grep "threshold" cupp.cfg

This outputs the configured value, confirming the memory boundary that will be enforced during wordlist generation.

Summary

  • The concatenation threshold is defined in cupp.cfg under the [nums] section and defaults to 200
  • CUPP loads this value at startup in cupp.py (line 71) and enforces it before concatenating words (lines 208-215)
  • The threshold prevents memory exhaustion by limiting the n × n combinations generated when concatenating wordlists
  • Users can adjust the threshold to balance between dictionary size and available RAM, or set it to 0 to disable concatenation entirely

Frequently Asked Questions

What happens if I set the concatenation threshold to 0?

Setting threshold=0 in cupp.cfg effectively disables the concatenation safeguard. However, since CUPP checks if the wordlist length exceeds the threshold, a value of 0 means any wordlist with 1 or more words will trigger the warning prompt. To completely skip concatenation, answer n when prompted or avoid using the -w flag.

How much memory does wordlist concatenation consume?

Memory consumption scales quadratically with wordlist size. A wordlist of n words creates up to n² concatenated strings. For example, 200 words generate 40,000 new strings, while 1,000 words generate 1,000,000 strings. Each string resides in memory until written to disk, meaning a 1,000-word concatenation could consume several hundred megabytes of RAM depending on average word length.

Can I disable the concatenation warning without changing the config file?

No, the threshold check is mandatory in the source code. The only way to bypass the warning for large wordlists is to answer Y when prompted, or to edit cupp.cfg to raise the threshold value before running CUPP. There is no command-line flag to override this memory protection mechanism.

Where is the concatenation logic implemented in the source code?

The concatenation logic and threshold check are implemented in cupp.py between lines 208-215. The configuration is read from cupp.cfg and stored in the global CONFIG dictionary at line 71. The actual string concatenation occurs after the threshold check passes, where CUPP combines every word in the list with every other word to generate permutations.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →