#VU119151 Use of hard-coded cryptographic key in Apache StreamPark - CVE-2025-53960
Published: December 4, 2025
Apache StreamPark
Apache Foundation
Description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to the application is using a hard-coded immutable key for encryption instead of dynamically generating or securely configuring the key. A remote attacker with ability to obtain the key can decrypt sensitive data or bypass authorization checks.