FlawAtlas
Search the atlas
CVE-2025-1293 High

Hermes improperly validates a JWT in github.com/hashicorp-forge/hermes

Hermes improperly validates a JWT in github.com/hashicorp-forge/hermes

Exploit probability 0.3%
Published March 3, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

5 explicit affected versions

Go github.com/hashicorp-forge/hermes
Go github.com/hashicorp-forge/hermes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3475

Hermes improperly validates a JWT in github.com/hashicorp-forge/hermes

View original source
Open Source Vulnerabilities GHSA-vxm9-8mfw-vc6g

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

View original source
Open Source Vulnerabilities CVE-2025-1293

Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.

View original source

05 / REFERENCES

Further evidence