github.com/hashicorp/vault
A tool for secrets management, encryption as a service, and privileged access management
Activity
- Latest release
- Feb 03, 2026
- Total releases
- 50
- Cadence
- ~42 days
- Last 12 months
- 3
Reach
- Stars
- 36.0k
Details
- First release
- Jul 13, 2015
| Version | Released | |
|---|---|---|
v1.21.3
minor
4 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev |
v1.21.3
minor
Dependencies (207)
+ 199 more |
|
v1.21.0-rc1
pre
6 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-12044
GO-2025-4071
BIT-vault-2025-12044
GHSA-vp5w-xcfc-73wf
Oct 30, 2025
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.21.0-rc1
pre
Dependencies (207)
+ 199 more |
|
v1.20.3
minor
6 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-12044
GO-2025-4071
BIT-vault-2025-12044
GHSA-vp5w-xcfc-73wf
Oct 30, 2025
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.20.3
minor
Dependencies (208)
+ 200 more |
|
v1.16.0
minor
22 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4656
GO-2025-3788
BIT-vault-2025-4656
GHSA-fhc2-8qx8-6vj7
Jul 28, 2025
Vault Community Edition rekey and recovery key operations can cause denial of service in github.com/hashicorp/vault Vault Community Edition rekey and recovery key operations can cause denial of service in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (208)
+ 200 more |
|
v1.13.10
patch
23 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.13.10
patch
Dependencies (198)
+ 190 more |
|
v1.15.0
minor
27 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4656
GO-2025-3788
BIT-vault-2025-4656
GHSA-fhc2-8qx8-6vj7
Jul 28, 2025
Vault Community Edition rekey and recovery key operations can cause denial of service in github.com/hashicorp/vault Vault Community Edition rekey and recovery key operations can cause denial of service in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0831
GO-2024-2511
BIT-vault-2024-0831
GHSA-vgh3-mwxq-rcp8
Jun 28, 2024
Hashicorp Vault may expose sensitive log information in github.com/hashicorp/vault Hashicorp Vault may expose sensitive log information in github.com/hashicorp/vault Fixed in
1.15.5
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.15.0
minor
Dependencies (208)
+ 200 more |
|
v1.13.8
patch
24 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.13.8
patch
Dependencies (197)
+ 189 more |
|
v1.14.2
minor
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5052
GO-2026-5262
BIT-vault-2026-5052
GHSA-8r5m-3f66-qpr3
Jun 25, 2026
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.14.2
minor
Dependencies (203)
+ 195 more |
|
v1.13.5
patch
25 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.13.5
patch
Dependencies (197)
+ 189 more |
|
v1.12.9
patch
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.12.9
patch
Dependencies (190)
+ 182 more |
|
v1.12.8
patch
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.12.8
patch
Dependencies (190)
+ 182 more |
|
v1.13.4
patch
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.13.4
patch
Dependencies (197)
+ 189 more |
|
v1.14.0-rc1
pre
22 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.14.0-rc1
pre
Dependencies (201)
+ 193 more |
|
v1.12.7
minor
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev |
v1.12.7
minor
Dependencies (190)
+ 182 more |
|
v1.11.10
patch
26 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.11.10
patch
Dependencies (180)
+ 172 more |
|
v1.13.0
minor
30 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6004
GO-2025-3840
BIT-vault-2025-6004
GHSA-qgj7-fmq2-6cc4
Aug 11, 2025
Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-6337
GO-2023-2399
BIT-vault-2023-6337
GHSA-6p62-6cg9-f5f5
Jan 03, 2024
Denial of service via memory exhaustion in github.com/hashicorp/vault Unauthenticated and authenticated HTTP requests from a client will be attempted to be mapped to memory. Large requests may result in the exhaustion of available memory on the host, which may cause crashes and denial of service. Fixed in
1.13.12
1.14.8
1.15.4
References Updated May 20, 2024 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.13.0
minor
Dependencies (196)
+ 188 more |
|
v1.11.5
patch
30 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.11.5
patch
Dependencies (179)
+ 171 more |
|
v1.12.0-rc1
pre
25 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.12.0-rc1
pre
Dependencies (189)
+ 181 more |
|
v1.10.6
patch
31 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.10.6
patch
Dependencies (177)
+ 169 more |
|
v1.11.1
minor
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.11.1
minor
Dependencies (179)
+ 171 more |
|
v1.10.5
patch
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.10.5
patch
Dependencies (177)
+ 169 more |
|
v1.11.0-rc1
pre
29 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.11.0-rc1
pre
Dependencies (179)
+ 171 more |
|
v1.10.3
minor
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6015
GO-2025-3842
BIT-vault-2025-6015
GHSA-v6r4-35f9-9rpw
Aug 11, 2025
Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2025-3879
GO-2025-3662
BIT-vault-2025-3879
GHSA-f9ch-h8j7-8jwg
May 06, 2025
Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault Fixed in
1.19.1
References Updated May 07, 2025 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-6468
GO-2024-2982
BIT-vault-2024-6468
GHSA-2qmw-pvf7-4mw6
Jul 12, 2024
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.12. Fixed in
1.16.3
1.17.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.10.3
minor
Dependencies (177)
+ 169 more |
|
v1.9.5
patch
29 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.5
patch
Dependencies (172)
+ 164 more |
|
v1.10.0-rc1
pre
27 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.10.0-rc1
pre
Dependencies (177)
+ 169 more |
|
v1.7.10
patch
29 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.10
patch
Dependencies (148)
+ 140 more |
|
v1.9.2
minor
29 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.9.2
minor
Dependencies (172)
+ 164 more |
|
v1.7.6
patch
28 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (148)
+ 140 more |
|
v1.8.4
patch
31 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-42135
GO-2022-0578
BIT-vault-2021-42135
GHSA-362v-wg5p-64w2
Aug 21, 2024
Incorrect Privilege Assignment in HashiCorp Vault in github.com/hashicorp/vault Incorrect Privilege Assignment in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.8.5
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (155)
+ 147 more |
|
v1.6.7
patch
30 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.7
patch
Dependencies (141)
+ 133 more |
|
v1.7.4
minor
30 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.7.4
minor
Dependencies (147)
+ 139 more |
|
v1.6.6
patch
30 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.6
patch
Dependencies (141)
+ 133 more |
|
v1.8.1
minor
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2022-40186
GO-2022-1021
BIT-vault-2022-40186
GHSA-7cgv-v83v-rr87
Aug 21, 2024
HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault Fixed in
1.9.9
1.10.6
1.11.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-42135
GO-2022-0578
BIT-vault-2021-42135
GHSA-362v-wg5p-64w2
Aug 21, 2024
Incorrect Privilege Assignment in HashiCorp Vault in github.com/hashicorp/vault Incorrect Privilege Assignment in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.8.5
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (156)
+ 148 more |
|
v1.8.0-rc2
pre
29 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-7594
GO-2024-3162
BIT-openbao-2024-7594
BIT-vault-2024-7594
GHSA-jg74-mwgw-v6x3
Oct 09, 2024
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault Fixed in
1.17.6
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.8.0-rc2
pre
Dependencies (155)
+ 147 more |
|
v1.6.2
minor
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-4680
GO-2023-2063
BIT-vault-2023-4680
GHSA-v84f-6r39-cpfc
Aug 21, 2024
HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault HashiCorp Vault Improper Input Validation vulnerability in github.com/hashicorp/vault Fixed in
1.12.11
1.13.7
1.14.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.6.2
minor
Dependencies (141)
+ 133 more |
|
v1.4.7
minor
32 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38553
GO-2022-0620
BIT-vault-2021-38553
GHSA-23fq-q7hc-993r
Aug 21, 2024
HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 in github.com/hashicorp/vault Fixed in
1.8.0
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.7
minor
Dependencies (122)
+ 114 more |
|
v1.3.8
patch
31 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.8
patch
Dependencies (113)
+ 105 more |
|
v1.3.7
patch
33 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.7
patch
Dependencies (113)
+ 105 more |
|
v1.3.5
minor
34 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-8185
GO-2024-3246
BIT-openbao-2024-8185
BIT-vault-2024-8185
GHSA-g233-2p4r-3q7v
Nov 01, 2024
Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault Fixed in
1.18.1
References
Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-13223
GO-2022-0778
BIT-vault-2020-13223
GHSA-25xj-89g5-fm6h
Aug 21, 2024
Information Disclosure in HashiCorp Vault in github.com/hashicorp/vault Information Disclosure in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.6
1.4.2
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.5
minor
Dependencies (113)
+ 105 more |
|
v1.2.0-beta2
pre
35 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-7220
GO-2022-0816
BIT-vault-2020-7220
GHSA-9vh5-r4qw-v3vv
Aug 21, 2024
Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10661
GO-2024-2485
BIT-vault-2020-10661
GHSA-j6vv-vv26-rh7c
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0-beta2
pre
Dependencies (103)
+ 95 more |
|
v1.1.0
minor
35 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-7220
GO-2022-0816
BIT-vault-2020-7220
GHSA-9vh5-r4qw-v3vv
Aug 21, 2024
Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10661
GO-2024-2485
BIT-vault-2020-10661
GHSA-j6vv-vv26-rh7c
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
|
|
v1.1.0-beta2
pre
35 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-7220
GO-2022-0816
BIT-vault-2020-7220
GHSA-9vh5-r4qw-v3vv
Aug 21, 2024
Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10661
GO-2024-2485
BIT-vault-2020-10661
GHSA-j6vv-vv26-rh7c
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0-beta2
pre
|
|
v1.0.1
major
35 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-7220
GO-2022-0816
BIT-vault-2020-7220
GHSA-9vh5-r4qw-v3vv
Aug 21, 2024
Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-25816
GO-2024-2514
BIT-vault-2020-25816
GHSA-57gg-cj55-q5g2
Jun 28, 2024
Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Token leases could outlive their TTL in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.5.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10661
GO-2024-2485
BIT-vault-2020-10661
GHSA-j6vv-vv26-rh7c
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.1
major
|
|
v1.0.0-beta2
pre
34 CVEs
CVE-2026-3605
GO-2026-5487
BIT-vault-2026-3605
GHSA-m2w4-8ggf-rj47
Jun 25, 2026
HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-4525
GO-2026-5199
BIT-vault-2026-4525
GHSA-72gw-fmmr-c4r4
Jun 25, 2026
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5999
GO-2025-3837
BIT-vault-2025-5999
GHSA-6h4p-m86h-hhgh
Aug 11, 2025
Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.20.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-7220
GO-2022-0816
BIT-vault-2020-7220
GHSA-9vh5-r4qw-v3vv
Aug 21, 2024
Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.3.2
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-43998
GO-2022-0611
BIT-vault-2021-43998
GHSA-pfmw-vj74-ph8g
Aug 21, 2024
HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault HashiCorp Vault Incorrect Permission Assignment for Critical Resource in github.com/hashicorp/vault Fixed in
1.7.6
1.8.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-32923
GO-2022-0623
BIT-vault-2021-32923
GHSA-38j9-7pp9-2hjw
Aug 21, 2024
Invalid session token expiration in github.com/hashicorp/vault Invalid session token expiration in github.com/hashicorp/vault Fixed in
1.5.9
1.6.5
1.7.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5798
GO-2024-2921
BIT-vault-2024-5798
GHSA-32cj-5wx4-gq8p
Jul 01, 2024
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims in github.com/hashicorp/vault. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: github.com/hashicorp/vault before v1.15.9. Fixed in
1.16.3
1.17.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10661
GO-2024-2485
BIT-vault-2020-10661
GHSA-j6vv-vv26-rh7c
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-beta2
pre
|
|
v0.9.4
minor
26 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6000
GO-2025-3838
BIT-vault-2025-6000
GHSA-mr4h-qf9j-f665
Aug 11, 2025
Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2020-16250
GO-2022-0825
BIT-vault-2020-16250
GHSA-fp52-qw33-mfmw
Aug 21, 2024
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0620
GO-2023-1685
BIT-vault-2023-0620
GHSA-v3hp-mcj5-pg39
Aug 20, 2024
HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault HashiCorp Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-16251
GO-2024-2488
BIT-vault-2020-16251
GHSA-4mp7-2m29-gqxf
Jun 28, 2024
HashiCorp Vault Authentication bypass in github.com/hashicorp/vault HashiCorp Vault Authentication bypass in github.com/hashicorp/vault Fixed in
1.2.5
1.3.8
1.4.4
1.5.1
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-10660
GO-2024-2486
BIT-vault-2020-10660
GHSA-m979-w9wj-qfj9
Jun 28, 2024
HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault HashiCorp Vault Improper Privilege Management in github.com/hashicorp/vault Fixed in
1.3.4
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.9.4
minor
|
|
v0.7.0-beta1
pre
21 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.7.0-beta1
pre
|
|
v0.6.4
minor
21 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.4
minor
|
|
v0.6.1-rc1
pre
21 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-11621
GO-2025-4070
BIT-vault-2025-11621
GHSA-9g4h-h484-3578
Oct 30, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault Fixed in
1.21.0
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.1-rc1
pre
|
|
v0.6.0-beta1
pre
20 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-4166
GO-2025-3663
BIT-openbao-2025-4166
BIT-vault-2025-4166
GHSA-gcqf-f89c-68hv
May 06, 2025
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault Fixed in
1.19.3
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.6.0-beta1
pre
|
|
v0.2.0
initial
19 CVEs
CVE-2026-5807
GO-2026-5247
BIT-vault-2026-5807
GHSA-88v5-9hxc-f85r
Jun 25, 2026
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault References Updated Jul 02, 2026 · Source: OSV.dev
CVE-2025-6203
GO-2025-3924
BIT-vault-2025-6203
GHSA-8f82-53h8-2p34
Sep 08, 2025
HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault Fixed in
1.20.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6011
GO-2025-3839
BIT-vault-2025-6011
GHSA-mwgr-84fv-3jh9
Aug 11, 2025
Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6037
GO-2025-3836
BIT-vault-2025-6037
GHSA-6c5r-4wfc-3mcx
Aug 11, 2025
Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6013
GO-2025-3848
BIT-vault-2025-6013
GHSA-7rx2-769v-hrwf
Aug 11, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault Fixed in
1.20.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-6014
GO-2025-3841
BIT-vault-2025-6014
GHSA-qv3p-fmv3-9hww
Aug 11, 2025
Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault Fixed in
1.20.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-9180
GO-2024-3191
BIT-openbao-2024-9180
BIT-vault-2024-9180
GHSA-rr8j-7w34-xp5j
Oct 11, 2024
Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault Fixed in
1.18.0
References Updated Jul 27, 2026 · Source: OSV.dev
CVE-2021-38554
GO-2022-0632
BIT-vault-2021-38554
GHSA-6239-28c2-9mrm
Aug 21, 2024
Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault in github.com/hashicorp/vault Fixed in
1.6.6
1.7.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41802
GO-2022-0618
BIT-vault-2021-41802
GHSA-qv95-g3gm-x542
Aug 21, 2024
Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Hashicorp Vault Privilege Escalation Vulnerability in github.com/hashicorp/vault Fixed in
1.7.5
1.8.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5954
GO-2023-2329
BIT-vault-2023-5954
GHSA-4qhc-v8r6-8vwm
Aug 21, 2024
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability in github.com/hashicorp/vault Fixed in
1.13.10
1.14.6
1.15.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5077
GO-2023-2088
BIT-vault-2023-5077
GHSA-86c6-3g63-5w64
Aug 21, 2024
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability in github.com/hashicorp/vault Fixed in
1.13.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3462
GO-2023-1986
BIT-vault-2023-3462
GHSA-9v3w-w2jh-4hff
Aug 20, 2024
HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault HashiCorp Vault and Vault Enterprise vulnerable to user enumeration in github.com/hashicorp/vault Fixed in
1.13.5
1.14.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-24999
GO-2023-1900
BIT-vault-2023-24999
GHSA-wmg5-g953-qqfw
Aug 20, 2024
Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Hashicorp Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation in github.com/hashicorp/vault Fixed in
1.10.11
1.11.8
1.12.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-41316
GO-2023-1897
BIT-vault-2022-41316
GHSA-9mh8-9j64-443f
Aug 20, 2024
HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault HashiCorp Vault's revocation list not respected in github.com/hashicorp/vault Fixed in
1.9.10
1.10.7
1.11.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2121
GO-2023-1849
BIT-vault-2023-2121
GHSA-gq98-53rq-qr5h
Aug 20, 2024
Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Hashicorp Vault vulnerable to Cross-site Scripting in github.com/hashicorp/vault Fixed in
1.11.11
1.12.7
1.13.3
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-0665
GO-2023-1708
BIT-vault-2023-0665
GHSA-hwc3-3qh6-r4gg
Aug 20, 2024
HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault HashiCorp Vault's PKI mount vulnerable to denial of service in github.com/hashicorp/vault Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2660
GO-2024-2690
BIT-vault-2024-2660
GHSA-j2rp-gmqv-frhv
Jun 04, 2024
HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault HashiCorpVault does not correctly validate OCSP responses in github.com/hashicorp/vault Fixed in
1.16.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-2048
GO-2024-2617
BIT-vault-2024-2048
GHSA-r3w7-mfpm-c2vw
Mar 14, 2024
Authentication bypass in github.com/hashicorp/vault The TLS certificate authentication method incorrectly validates client certificates when configured with a non-CA certificate as a trusted certificate. When configured this way, attackers may be able to craft a certificate that can be used to bypass authentication. Fixed in
1.14.10
1.15.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-25000
GO-2023-1709
BIT-vault-2023-25000
GHSA-vq4h-9ghm-qmrr
Apr 12, 2023
Cache-timing attacks in Shamir's secret sharing in github.com/hashicorp/vault HashiCorp Vault's implementation of Shamir's secret sharing uses precomputed table lookups, and is vulnerable to cache-timing attacks. An attacker with access to, and the ability to observe a large number of unseal operations on the host through a side channel may reduce the search space of a brute force effort to recover the Shamir shares. Fixed in
1.11.9
1.12.5
1.13.1
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.2.0
initial
|