CVE-2025-1293 Information
Feb 21, 2025
cve
Description
Hermes versions up to 0.4.0 improperly validated the JWT provided when using the AWS ALB authentication mode potentially allowing for authentication bypass. This vulnerability CVE-2025-1293 was fixed in Hermes 0.5.0.