CVE-2025-22228

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 287

Summary

CVE-2025-22228 is a vulnerability affecting BCryptPasswordEncoder's `matches` method. This issue causes the function to incorrectly return a match result for passwords exceeding 72 characters, as long as the first 72 characters are identical. Consequently, weak or repetitive passwords longer than 72 characters may be erroneously considered secure, posing a potential security risk. It is recommended that users upgrade their libraries to mitigate this vulnerability and enforce stricter password policies.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share