Exploit for CVE-2025-22228

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

Published: 2025-03-20

CVSS: 7.4

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Download Exploit for CVE-2025-22228 here:

Use Tor Browser to access .onion links.

Check our team here:

https://tatramed.sk/exploit-447-cve-2025-54982/

https://tatramed.sk/exploit-719-cve-2025-59499/

https://tatramed.sk/exploit-512-cve-2024-20926/

https://tatramed.sk/exploit-1095-cve-2022-33679/