If the input is 71 character, all the libraries happily accept it, but an attacker needs to guess only 1 character.
72 is the max length of id, username, and password combined. If that combination is over 72, then failure and the cache key would not have been created. So, no, the attacker would not need to guess only one character of a password.