CVE-2025-22228
ADVISORY - githubSummary
BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
EPSS Score: 0.00032 (0.092)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Authentication
ADVISORY - gitlab
ADVISORY - redhat
Incorrect Authorization
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in