CVE-2025-54981

CVE-2025-54981: Apache StreamPark: Weak Encryption Algorithm in StreamPark

Vendor Apache Software Foundation
Product Apache StreamPark
Weakness CWE-327 · Broken crypto
Published December 12, 2025
Last update December 12, 2025

CVSS base score

What the vulnerability does

Description

Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2.0.0 before 2.1.7. Users are recommended to upgrade to version 2.1.7, which fixes the issue.

Key dates

Disclosure timeline

December 12, 2025 CVE published
December 12, 2025 Record updated