PT-2025-12012 · Unknown+1 · Bcryptpasswordencoder+3

CVE-2025-22228

·

Published

2025-03-20

·

Updated

2026-07-29

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions BCryptPasswordEncoder (affected versions not specified)
Description The issue concerns the BCryptPasswordEncoder, where the matches(CharSequence, String) function will incorrectly return true for passwords larger than 72 characters, as long as the first 72 characters are the same.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-22228
ECHO-0D82-8E9F-D92A
GHSA-MG83-C7GQ-RV5C
RHSA-2025:10092
RHSA-2025:10097
RHSA-2025:10098
RHSA-2025:10104
RHSA-2025:10118
RHSA-2025:10119
RHSA-2025:10120

Affected Products

Bcryptpasswordencoder
Bamboo
Bitbucket
Confluence