hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability poses a critical security risk in systems where authentication and authorization rely on the integrity of JWTs.
                
            References
                    Configurations
                    No configuration.
History
                    22 Aug 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CWE | CWE-798 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 8.8 | 
21 Aug 2025, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-21 21:15
Updated : 2025-08-22 18:08
NVD link : CVE-2025-51606
Mitre link : CVE-2025-51606
CVE.ORG link : CVE-2025-51606
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-798
                        
            Use of Hard-coded Credentials
