Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 522

Hash Collision

Reviewed byCybersecurity entrepreneur & security researcher

What is Hash Collision?

Hash CollisionTwo distinct inputs that produce the same cryptographic hash value, breaking integrity, uniqueness, and signature guarantees that depend on the hash function.


A hash collision is a pair of different inputs that map to identical hash outputs. Because hash functions compress arbitrary data to a fixed size, collisions exist mathematically, but a secure hash makes them computationally infeasible to find. The generic birthday bound means a brute-force collision needs only about 2^(n/2) work — 2^128 for SHA-256 — so a broken function is one where mathematical shortcuts drop that cost far lower.

Two collision classes matter. An identical-prefix collision appends crafted blocks to a shared prefix; the chosen-prefix collision, far more dangerous, lets an attacker start from two arbitrary, meaningful prefixes and still collide, which is what forges certificates and keys.

Real breaks: Wang et al. found practical MD5 collisions in 2004; in 2008 Sotirov, Stevens et al. minted a rogue CA certificate, and in 2012 the Flame espionage malware used a novel MD5 chosen-prefix collision to forge a Microsoft Terminal Server Licensing certificate and sign malware as Microsoft. SHA-1 fell to Google/CWI's SHAttered identical-prefix collision in 2017 (~2^63 work), then to Leurent and Peyrin's SHA-1 is a Shambles chosen-prefix collision in 2020, which forged a PGP key certification (GnuPG CVE-2019-14855, fixed in 2.2.18).

Defence: retire MD5 and SHA-1 for any security use and adopt SHA-256, SHA-3, or BLAKE2/BLAKE3, per NIST's deprecation of SHA-1.

flowchart TD
  A[Attacker picks two prefixes P1 and P2] --> B[Collision search: compute near-collision blocks]
  B --> C{H of P1 plus blocks equals H of P2 plus blocks?}
  C -->|No| B
  C -->|Yes| D[Benign document D1 and malicious document D2 share one hash]
  D --> E[Victim signs or trusts D1]
  E --> F[Signature or trust transfers to D2]
  F --> G[Forged certificate, key, or binary accepted]

● Examples

  1. 01

    The 2017 SHAttered PDF pair from Google and CWI showed two PDFs with the same SHA-1 hash.

  2. 02

    Flame (2012) used an MD5 chosen-prefix collision to forge a Microsoft Terminal Server license certificate.

● Frequently asked questions

What is Hash Collision?

Two distinct inputs that produce the same cryptographic hash value, breaking integrity, uniqueness, and signature guarantees that depend on the hash function. It belongs to the Cryptography category of cybersecurity.

What does Hash Collision mean?

Two distinct inputs that produce the same cryptographic hash value, breaking integrity, uniqueness, and signature guarantees that depend on the hash function.

How do you defend against Hash Collision?

Defences for Hash Collision typically combine technical controls and operational practices, as detailed in the full definition above.

● Related terms