Back to Database
Status published
High
CVE-2025-22228
CVE-2025-22228: Spring Security BCryptPasswordEncoder does not enforce maximum password length
Vulnerability Description
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-22228
Credits & Attribution
No credits recorded in the NVD database.
References
More from Spring
View All →CVE-2025-41243
Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
Critical
10
CVE-2025-41232
CVE-2025-41232: Spring Security authorization bypass for method security annotations on private methods
Critical
9.1
CVE-2025-22235
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
High
7.3
CVE-2025-22234
Spring Security - BCrypt Password Encoder maximum password length breaks timing attack mitigation
Medium
5.3
CVE-2025-22233
Spring Framework DataBinder Case Sensitive Match Exception
Low
3.1
Affected Vendor
Spring
View all reports →Affected Software
Spring Security
Vulnerable Versions:
5.7.x, 5.8.x, 6.0.x, 6.1.x, 6.2.x, 6.3.x, 6.4.x
Timeline
Official Publish:
March 20th, 2025
Last Modified:
February 26th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.