https://seclists.org/oss-sec/2025/q4/273: CVE-2025-54981: Apache StamPark: Weak Encryption Algorithm in StamPark
Published Dec 12, 2025
·Updated
Affected Software
1 affected component
Apache StreamPark<2.1.7
Frequently Asked Questions
1
What is the severity of CVE-2025-54981?
The severity of CVE-2025-54981 is classified as important.
2
Which versions of Apache StreamPark are affected by CVE-2025-54981?
Apache StreamPark versions prior to 2.1.7 are affected by CVE-2025-54981.
3
What is the primary security issue identified in CVE-2025-54981?
CVE-2025-54981 identifies a weak encryption algorithm due to the use of AES cipher in ECB mode.
4
How do I fix CVE-2025-54981?
To fix CVE-2025-54981, upgrade Apache StreamPark to version 2.1.7 or later.
5
What kind of data is at risk due to CVE-2025-54981?
CVE-2025-54981 risks exposing sensitive data, including JWT tokens, due to weak encryption methods.