All the vulnerabilities related to the version 0.7.4 of the package
Integer Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algorithm in bcrypt
In bcrypt (npm package) before version 5.0.0, data is truncated wrong when its length is greater than 255 bytes.