CVE-2025-22228 Information
Mar 21, 2025
cve
Description
BCryptPasswordEncoder.matches(CharSequenceString) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
Reference
https://spring.io/security/cve-2025-22228
Share on: