CVE-2025-25298: fallo de gravedad media en strapi
Missing Maximum Password Length Validation in Strapi Password Hashing
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.3epss 0.4%
probabilidad de explotación
0.4%top 68% de las CVE
explotación observada
noninguna fuente lo reporta
Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can create an account with a password exceeding 72 bytes and later authenticate with only the first 72 bytes. This reduces the effective entropy of overlong passwords and may mislead users who believe characters beyond 72 bytes are required, creating a low likelihood of unintended authentication if an attacker can obtain or guess the truncated portion. Long over‑length inputs can also impose unnecessary processing overhead. The issue is fixed in version 5.10.3. No known workarounds exist.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
strapi · strapiCVEs relacionadas — strapi
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-27886CRITICALStrapi may leak sensitive data via relational filtering due to lack of query sanitizationEPSS 2.5%CVE-2026-22599CRITICALStrapi Vulnerable to SQL Injection in Content Type BuilderEPSS 1.2%CVE-2023-34235HIGHLeaking sensitive user information still possible by filtering on private with prefix fieldsEPSS 1.1%CVE-2023-38507HIGHStrapi Improper Rate Limiting vulnerabilityEPSS 1.0%CVE-2024-31217MEDIUM@strapi/plugin-upload has a Denial-of-Service via Improper Exception HandlingEPSS 0.7%CVE-2023-34093MEDIUMStrapi allows actors to make all attributes on a content-type public without noticing itEPSS 0.7%