A critical vulnerability, tracked as CVE-2025-54947, was discovered in Apache StreamPark, a widely used stream-processing platform. The flaw arises from the use of a hard-coded encryption key and insecure AES ECB mode, allowing attackers to decrypt sensitive data, forge authentication tokens, and potentially gain unauthorized access to affected systems. The vulnerability impacts versions 2.0.0 through 2.1.7, exposing organizations to significant risks of information disclosure and privilege escalation if left unpatched.
The Apache StreamPark development team has addressed the issue by releasing version 2.1.7, which eliminates the hard-coded key vulnerability. Security experts strongly advise organizations to upgrade to the latest version immediately and conduct thorough security audits of their StreamPark deployments to identify and mitigate any potential compromise resulting from this flaw. Failure to patch could allow threat actors to manipulate system behavior or escalate privileges within enterprise environments relying on StreamPark for real-time data processing.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Apache StreamPark team released version 2.1.7 to fix CVE-2025-54947 and advised users to upgrade immediately. Reporting also recommended auditing affected environments for possible data exposure and reviewing key management practices.
A vulnerability affecting Apache StreamPark versions 2.0.0 through 2.1.7 was identified, caused by a hard-coded cryptographic key and use of insecure AES ECB mode. The issue could allow attackers to decrypt sensitive data and forge authentication tokens, leading to unauthorized access or privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.