—
GO-2025-3475
Hermes improperly validates a JWT in github.com/hashicorp-forge/hermes
Quick fix
GO-2025-3475 — github.com/hashicorp-forge/hermes: upgrade to the fixed version with the command below.
go get github.com/hashicorp-forge/hermes@v0.5.0Details
Hermes improperly validates a JWT in github.com/hashicorp-forge/hermes
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp-forge/hermes
Introduced in:
0Fixed in: 0.5.0Fix
go get github.com/hashicorp-forge/hermes@v0.5.0References
- https://github.com/advisories/GHSA-vxm9-8mfw-vc6g[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-1293[ADVISORY]
- https://github.com/hashicorp-forge/hermes/commit/e36d479616099bd0c8dfde6786ea671f112d9106[FIX]
- https://discuss.hashicorp.com/t/hcsec-2025-03-hashicorp-hermes-improperly-validates-aws-alb-jwts-which-may-lead-to-authentication-bypass/73371[WEB]