CVE-2025-22234
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
CVEs:CVE-2025-22234
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide
CVEs:CVE-2025-22234
GHSA-qpfh-2wpm-c362
CVEs:GHSA-qpfh-2wpm-c362
CVEs:CVE-2025-22232
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
CVEs:GHSA-rc42-6c7j-7h5r
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
CVEs:CVE-2025-22235
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.