CVE-2025-22228

ADVISORY - github

Summary

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

EPSS Score: 0.00032 (0.092)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Authentication

ADVISORY - github

Improper Authentication

Weak Password Requirements

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Improper Authentication

Weak Password Requirements

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Incorrect Authorization


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in