CVE-2025-1293

Source
https://cve.org/CVERecord?id=CVE-2025-1293
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-1293.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-1293
Aliases
Downstream
Related
Published
2025-02-20T00:28:37.246Z
Modified
2026-05-28T03:55:44.074364751Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
HashiCorp Hermes Improperly Validates AWS ALB JWTs, which May Lead to Authentication Bypass
Details

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1293.json",
    "cwe_ids": [
        "CWE-1390"
    ],
    "cna_assigner": "HashiCorp"
}
References

Affected packages

Git / github.com/hashicorp-forge/hermes

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp-forge/hermes
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.0.1
v0.1.0
v0.2.0
v0.3.0
v0.4.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-1293.json"