CVE-2025-1293: Hashicorp Hermes
High severity, CVSS 8.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.
Affected products
- Hashicorp Hermes: before 0.5.0 (fixed in 0.5.0)
Published 2025-02-20. Last modified 2026-06-17.