In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.springframework.security:spring-security-crypto
to version 6.3.9, 6.4.5 or higher.
org.springframework.security:spring-security-crypto is a spring-security-crypto library for Spring Security.
Affected versions of this package are vulnerable to Timing Attack due to an unintentional bypass for DaoAuthenticationProvider
constant time controls, which was caused by the fix for the password length vulnerability described in (CVE-2025-22228)[https://security.snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORKSECURITY-9486467].
Note: Patches have also been issued for older versions of Enterprise Support packages.