Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vqxh-445g-37fc: Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide

The fix applied in CVE-2025-22228 inadvertently broke the timing attack mitigation implemented in DaoAuthenticationProvider. This can allow attackers to infer valid usernames or other authentication behavior via response-time differences under certain configurations.

ghsa
#git#java#intel#oauth#auth#maven

Skip to content

Navigation Menu

    • AI CODE CREATION

      • GitHub CopilotWrite better code with AI

      • GitHub SparkBuild and deploy intelligent apps

      • GitHub ModelsManage and compare prompts

      • MCP RegistryNewIntegrate external tools

View all features
  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

Appearance settings

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-22234

Spring Security has a broken timing attack mitigation implemented in DaoAuthenticationProvide

Moderate severity GitHub Reviewed Published Jan 22, 2026 to the GitHub Advisory Database • Updated Jan 22, 2026

Package

maven org.springframework.security:spring-security-core (Maven)

Affected versions

= 6.3.8

= 6.4.4

Patched versions

6.3.9

6.4.5

Description

Published to the GitHub Advisory Database

Jan 22, 2026

Last updated

Jan 22, 2026

EPSS score

ghsa: Latest News

GHSA-cq3j-qj2h-6rv3: Container and Containerization archive extraction does not guard against escapes from extraction base directory.