CVE-2025-22234: Spring Security BCryptPasswordEncoder maximum password length breaks timing attack mitigation
Description
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider
.
Affected Spring Products and Versions
Spring Security:
- 5.7.16 only
- 5.8.18 only
- 6.0.16 only
- 6.1.14 only
- 6.2.10 only
- 6.3.8 only
- 6.4.4 only
- Older, unsupported versions are also affected …