CVE-2025-22234: Spring Security

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

Affected products

  • Spring Spring Security: version 5.7.16 only; version 5.8.18 only; version 6.0.16 only; version 6.1.14 only; version 6.2.10 only; version 6.3.8 only; …

Published 2026-01-22. Last modified 2026-06-17.