CVE-2025-25298
MEDIUMDescription
Strapi is an open source headless CMS. The @strapi/core package before version 5.10.3 does not enforce a maximum password length when using bcryptjs for password hashing. Bcryptjs ignores any bytes beyond 72, so passwords longer than 72 bytes are silently truncated. A user can create an account with a password exceeding 72 bytes and later authenticate with only the first 72 bytes. This reduces the effective entropy of overlong passwords and may mislead users who believe characters beyond 72 bytes are required, creating a low likelihood of unintended authentication if an attacker can obtain or guess the truncated portion. Long over‑length inputs can also impose unnecessary processing overhead. The issue is fixed in version 5.10.3. No known workarounds exist.
Is your site exposed to CVE-2025-25298?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| strapi | strapi |
References
Frequently Asked Questions
What is CVE-2025-25298? +
How severe is CVE-2025-25298? +
What products are affected by CVE-2025-25298? +
How do I check if I'm vulnerable to CVE-2025-25298? +
Related Vulnerabilities
Use of a custom password encoding algorithm in Streamsoft Prestiż software allows straightforward decoding of passwords using their encoded forms, …
The credentials required to access the device's web server are sent in base64 within the HTTP headers. Since base64 is …
The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within …
Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after …
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may …
Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data …