CVE-2025-22234: medium-severity vulnerability in Spring Security
Spring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigation
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.4%
exploitation probability
0.4%top 68% of all CVEs
observed exploitation
nono source reports it
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Spring · Spring SecurityRelated CVEs — Spring Security
In the same product, most dangerous first.
CVE-2019-3795LOWInsecure Randomness When Using a SecureRandom Instance Constructed by Spring SecurityEPSS 1.9%CVE-2019-11272—PlaintextPasswordEncoder authenticates encoded passwords that are nullEPSS 1.4%CVE-2024-22234HIGHCVE-2024-22234: Broken Access Control in Spring Security With Direct Use of isFullyAuthenticatedEPSS 0.7%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2025-22228HIGHCVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password lengthEPSS 0.6%CVE-2025-22223MEDIUMCVE-2025-22223EPSS 0.5%