The post discusses CVE-2025-22234, a vulnerability related to the maximum password length in BCryptPasswordEncoder, which affects its timing attack mitigation in Spring Security.

1m read timeFrom spring.io
Post cover image

Sort: