CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-54947: streampark from 2.0.0 (inclusive), before 2.1.7 (exclusive); +1 more affected products

CVE-2025-54947. CVSS 3.1 base score 9.8 (CRITICAL, NVD). EPSS 0.00478 (percentile 0.3922), scored 2026-10-06.

Affected technology

streampark · from 2.0.0 (inclusive), before 2.1.7 (exclusive)
apache

Apache StreamPark · 2.0.0 to before 2.1.7
Apache Software Foundation

Description’s affected range: versions 2.0.0 through 2.1.7

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers may obtain this key through reverse engineering or code analysis, potentially decrypting sensitive data or forging encrypted information, leading to information disclosure or unauthorized system access. NVD’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-321, CWE-798
CCR priority
39.3 /100 (P4)
CVSS 3.1
9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.00478 · percentile 0.3922 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-54947.html