Strapi is an open-source headless CMS. The vulnerability affects the password hashing implementation using bcryptjs, which lacks maximum password length validation. This creates potential vulnerabilities such as authentication bypass and performance degradation.