CVE-2025-51606
HIGHCn.hippo4j Hippo4j-core - Hard-coded Credentials
Title source: ruleDescription
hippo4j 1.0.0 to 1.5.0, uses a hard-coded secret key in its JWT (JSON Web Token) creation. This allows attackers with access to the source code or compiled binary to forge valid access tokens and impersonate any user, including privileged ones such as "admin". The vulnerability poses a critical security risk in systems where authentication and authorization rely on the integrity of JWTs.
Scores
CVSS v3
8.8
EPSS
0.0008
EPSS Percentile
23.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-798
Status
draft
Affected Products (1)
cn.hippo4j/hippo4j-core
Maven
Timeline
Published
Aug 21, 2025
Tracked Since
Feb 18, 2026