← Vulnerability feed

Vulnerability record · CVE-2025-54981 · published 12 December 2025

CVE-2025-54981: Apache streampark broken cryptographic algorithm vulnerability

Apache · Streampark

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

7.5 CVSS 3.1 High EPSS 0.24% · top 86.5% CWE-327 · Broken cryptographic algorithm
7.5CVSS 3.1 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54981 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54947Apache streampark hard-coded credentials vulnerabilityIn Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists. This vulnerability occurs b…EPSS 0.48%9.8CVE-2022-45802Apache streampark unrestricted file upload vulnerabilityStreampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file type, causing users to upload…EPSS 1.3%9.1CVE-2024-29070Apache streampark insufficient session expiration vulnerabilityOn versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" …EPSS 0.79%9.1CVE-2022-46365Apache streampark improper input validation vulnerabilityApache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a …EPSS 1.5%8.8CVE-2024-29178Apache streampark code injection vulnerabilityOn versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …EPSS 1.2%8.1CVE-2023-52290Apache streampark sql injection vulnerabilityIn streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-en…EPSS 0.64%7.6CVE-2024-48988Apache streampark sql injection vulnerabilitySQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to …EPSS 0.59%7.3CVE-2025-30001Apache streampark vulnerabilityIncorrect Execution-Assigned Permissions vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are…EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2025-54981), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.