Timing Attack Vulnerability in DaoAuthenticationProvider by Spring
CVE-2025-22234
What is CVE-2025-22234?
A vulnerability exists in the DaoAuthenticationProvider of Spring Security, where a fix for a previous issue unintentionally disabled the timing attack mitigation feature. This flaw could allow attackers to exploit response-time differences to infer valid usernames and potentially other authentication behavior, particularly under specific configurations. It is crucial for users of affected versions to apply necessary updates to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Security 5.7.16
Spring Security 5.7.16
Spring Security 5.8.18
News Articles
Spring Security Vulnerability Exposes Valid Usernames to Attackers
A newly identified security vulnerability, CVE-2025-22234, has exposed a critical weakness in the widely-used Spring Security framework.
References
CVSS V3.1
Timeline
Vulnerability published
- ๐ฐ
First article discovered by GBHackers News
Vulnerability Reserved
