Medium severity5.3NVD Advisory· Published Jan 22, 2026· Updated Apr 15, 2026
CVE-2025-22234
CVE-2025-22234
Description
The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.security:spring-security-coreMaven | >= 6.3.8, < 6.3.9 | 6.3.9 |
org.springframework.security:spring-security-coreMaven | >= 6.4.4, < 6.4.5 | 6.4.5 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.