CVE-2025-51606
Last modified
CVE-2025-51606 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability poses a critical security risk in systems where authentication and authorization rely on the integrity of JWTs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-51606?
How severe is CVE-2025-51606?
How do I fix CVE-2025-51606?
Are you affected by CVE-2025-51606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
