← Back

Hermes

hermes

Vendor: Hashicorp • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hashicorp
1Hermes
Jun 17, 2026
Feb 20, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode, potentially allowing for authentication bypass. This vulnerability, CVE-2025-1293, was fixed in Hermes 0.5.0.