BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
This issue has been addressed in the following products: Red Hat build of Apache Camel 4.8.5 for Spring Boot Via RHSA-2025:3543 https://access.redhat.com/errata/RHSA-2025:3543