VYPR

Hermes

by Hashicorp

CVEs (1)

  • CVE-2025-1293HigFeb 20, 2025
    risk 0.46cvss 8.2epss 0.00

    Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.