HashiCorp HashiCorp

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any HashiCorp product.

RSS Feeds for HashiCorp security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in HashiCorp products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by HashiCorp Sorted by Most Security Vulnerabilities since 2018

HashiCorp Vault76 vulnerabilities

HashiCorp Consul44 vulnerabilities

HashiCorp Nomad41 vulnerabilities

HashiCorp Go Getter9 vulnerabilities

HashiCorp Boundary6 vulnerabilities

HashiCorp Terraform4 vulnerabilities

HashiCorp Packer3 vulnerabilities

HashiCorp Sentinel2 vulnerabilities

HashiCorp Vagrant2 vulnerabilities

HashiCorp Go Slug2 vulnerabilities

HashiCorp Retryablehttp1 vulnerability

HashiCorp Consul Template1 vulnerability

HashiCorp Vault Action1 vulnerability

By the Year

In 2026 there have been 38 vulnerabilities in HashiCorp with an average score of 6.8 out of ten. Last year, in 2025 HashiCorp had 23 security vulnerabilities published. That is, 15 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.30




Year Vulnerabilities Average Score
2026 38 6.77
2025 23 7.07
2024 24 6.38
2023 30 6.44
2022 31 7.16
2021 32 7.07
2020 27 7.40
2019 5 0.00
2018 4 7.28

It may take a day or so for new HashiCorp vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent HashiCorp Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-5006 Aug 24, 2026
Auth Bypass via Identity Path Manipulation in HashiCorp Vault 2.0.4 A vulnerability was identified in HashiCorp Vault and Vault Enterprise (Vault) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can control the referenced identity value may include slash ({{/}}) characters that Vault interprets as additional path segments when rendering the policy. This vulnerability, CVE-2026-5006, was fixed in Vault Community Edition 2.0.4 and Vault Enterprise 2.0.4, 1.21.9, 1.20.14, and 1.19.20.
Vault
CVE-2026-14978 Aug 19, 2026
HashiCorp go-slug 0.4.00.18.2 Unicode Normalization .terraformignore Bypass HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
Go Slug
CVE-2026-19589 Aug 17, 2026
Packer <=1.15.4 Plugin Installer FS Modification CVE-2026-19589 Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.
Packer
CVE-2026-8715 Aug 13, 2026
Vault Secrets Op 1.3.0-1.4.1: AppRole Auth Enables File Read & Credential Leak Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
CVE-2026-14886 Aug 10, 2026
Vault Enterprise NS Auth Bypass via Batch-Delete (pre-2.0.4/1.21.9) Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated caller in one namespace to permanently delete the storage backing of entities belonging to another namespace. This vulnerability (CVE-2026-14886) is fixed in Vault Enterprise 2.0.4, 1.21.9, 1.20.14 and 1.19.20.
Vault
CVE-2026-12624 Aug 10, 2026
Vault ACL Engine ignores glob deny on LIST for trailing slash pre-2.0.3/1.21.8 Vaults ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token holding a broader allow rule alongside a narrower wildcard deny rule to enumerate the names of entries beneath a path it was intended to be denied access to. This vulnerability (CVE-2026-12624) is fixed in Vault Community Edition 2.0.3 and Vault Enterprise 2.0.3, 1.21.8, 1.20.13, and 1.19.19.
Vault
CVE-2026-19113 Aug 07, 2026
Consul HTTP API Excess Memory: Unauth DoS 1.3.0-2.0.2 Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API endpoints. A remote caller could cause the agent to consume substantial memory before the request was rejected. This vulnerability, CVE-2026-19113, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-15972 Aug 07, 2026
Consul 1.13.0-2.0.2 Unauthenticated DoS via Unbounded gRPC Listener Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connection acceptance on the external gRPC listeners. A remote attacker may exhaust agent file descriptors, goroutines, and memory by opening many incomplete connections, potentially preventing legitimate clients from connecting. This vulnerability, CVE-2026-15972, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-15970 Aug 07, 2026
Consul L7 Intent Auth Bypass via Custom Public Listener (<=2.0.2) Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-19017 Aug 07, 2026
Consul CE/Ent 1.18.21-2.0.2 Partial File Read via Vault CA JWT/AppRole Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault Connect CA provider with JWT or AppRole authentication. A privileged attacker with `operator:write` permission may direct Consul to read and forward credential files outside the intended scope, potentially leading to the exfiltration of sensitive secrets from the Consul server host. This vulnerability, CVE-2026-19017, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-19015 Aug 07, 2026
Unbounded Cache Growth in Consul Connect CA Roots (1.2.02.0.2) Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roots endpoint that may allow a remote caller to grow the agent's Connect CA roots cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-19015, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-19014 Aug 07, 2026
Uncontrolled Resource Consumption in Consul Connect Auth Endpt 1.17-2.0.2 Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect authorization endpoint that may allow a caller to grow the agent's intention-match cache without bound, defeating the operator's cache-disable configuration. This vulnerability, CVE-2026-190124, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-19012 Aug 07, 2026
Consul Auth-DOS: service-router config downgrade crash Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Community Edition downgrade path that may allow an authorized caller to crash the Consul server. A caller with config-entry write permission can submit a service-router configuration entry that causes the agent to exit unexpectedly. This vulnerability, CVE-2026-19012, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-19016 Aug 07, 2026
Consul txAPI Session Delete ACL Flaw v1.19.12.0.2 Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
Consul
CVE-2026-16326 Jul 29, 2026
Session State Leak in consul-mcp-server 0.1.0-0.1.3 (CVE-2026-16326) In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.
CVE-2026-16328 Jul 29, 2026
consul-mcp-server 0.1.0-3 Header Injection Allows Redirect to Consul API In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to override the server's configured Consul address via a request header. This may allow a malicious client to redirect the server's Consul API traffic to an attacker-controlled endpoint, potentially exfiltrating the Consul token configured on the server. This vulnerability, CVE-2026-16328, is fixed in consul-mcp-server 0.1.4.
CVE-2026-16498 Jul 28, 2026
Terraform-MCP-Server <1.1.0: Cross-Tenant Credential Reuse via Streamable-HTTP The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool calls on behalf of subsequent users. This vulnerability, CVE-2026-16498, is fixed in terraform-mcp-server 1.1.0.
CVE-2026-16496 Jul 28, 2026
terraform-mcp-server v1.1.0 Auth Bypass in Streamable-HTTP Mode The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another user's MCP session ID to have their tool calls executed using that user's Terraform credentials. This vulnerability, CVE-2026-16496, is fixed in terraform-mcp-server 1.1.0.
CVE-2026-14869 Jul 28, 2026
terraform-mcp-server SSRF in streamable-HTTP before 1.1.0 The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an unauthenticated remote client to redirect the server's Terraform API requests, and the server-side authorization token, to an attacker-controlled endpoint. This vulnerability, CVE-2026-14869, is fixed in terraform-mcp-server 1.1.0.
CVE-2026-14896 Jul 08, 2026
Nomad 2.0.4/1.11.8/1.10.14: CrossNS Auth Bypass in Host Volumes HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Nomad
CVE-2026-14361 Jul 08, 2026
consultemplate 0.42.1: Path Redirection in writeToFile (CVE2026-14361) The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template helper that may allow template output to be written outside the intended directory or to overwrite an existing file. This vulnerability (CVE-2026-14361) is fixed in consul-template 0.42.1.
CVE-2026-14891 Jul 08, 2026
Nomad Docker Driver Sandbox Escape via Unauthorized Bind-Mount Before 2.0.4 HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Nomad
CVE-2026-14373 Jul 08, 2026
HashiCorp Nomad: allow_privileged Not Enforced (pre 2.0.4/1.11.8/1.10.14) HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
Nomad
CVE-2026-14362 Jul 08, 2026
HashiCorp memberlist <0.6.0 DoS via Push/Pull Gossip Port HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling that may allow an attacker with network access to the gossip port to exhaust memory on a receiving node and cause the process to terminate. This vulnerability (CVE-2026-14362) is fixed in memberlist 0.6.0.
CVE-2026-14468 Jul 06, 2026
Terraform Enterprise VCS Module Ingestion Path Traversal (CVE-2026-14468) HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on packaged module content. This may allow an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files readable by the ingestion process. This vulnerability, CVE-2026-14468, is fixed in Terraform Enterprise v2.0.4 and v1.2.4.
Terraform Enterprise
CVE-2026-5051 Jul 01, 2026
HashiCorp Vault Audit Plugin Directory Protections Flaw (pre-2.0.1) HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path option was used. This vulnerability (CVE-2026-5051) is fixed in 2.0.1, 1.21.6, 1.20.11, and 1.19.17.
Vault
CVE-2026-7474 May 12, 2026
Nomad Path Traversal CVE-2026-7474, Code Exec via Client Host, fixed in 2.0.1 HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Nomad
CVE-2026-8052 May 12, 2026
Nomad Exec2 Driver <0.1.2 Arbitrary File Read/Write via Symlink (CVE-2026-8052) HashiCorp Nomads exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.
CVE-2026-6959 May 12, 2026
Nomad <2.0.1: Arbitrary File Read/Write via Symlink Attack HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Nomad
CVE-2026-5061 May 12, 2026
consul-template <0.42.0 Sandbox Path Bypass via file template helper The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) is fixed in consul-template 0.42.0.
CVE-2026-7776 May 04, 2026
DoS in Boundary Workers TLS Handshake (fixed 0.21.3, 0.20.3, 0.19.5) Boundary Community Edition and Boundary Enterprise (Boundary) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes. An attacker with network access to the worker authentication listener may open a connection and delay or withhold the client certificate during the TLS handshake, causing worker connection handling to block. This may prevent legitimate worker connections from being accepted or routed. This vulnerability, CVE-2026-7776, is fixed in Boundary 0.21.3, 0.20.3, 0.19.5.
Boundary
CVE-2026-5807 Apr 17, 2026
Vault 2.0.0 DoS: Unauth Root Token Gen/Rekey ops slot Vault is vulnerable to a denial-of-service condition where an unauthenticated attacker can repeatedly initiate or cancel root token generation or rekey operations, occupying the single in-progress operation slot. This prevents legitimate operators from completing these workflows. This vulnerability, CVE-2026-5807, is fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0.
Vault
CVE-2026-4525 Apr 17, 2026
Vault Auth Header Forwarding CVE-2026-4525 (v2.0.0,1.21.5,1.20.10,1.19.16) If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to authenticate to Vault, Vault forwarded the Vault token to the auth plugin backend. Fixed in 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Vault
CVE-2026-5052 Apr 17, 2026
Vault ACME Validation Local-Target Disclosure (1.21.4, 2.0.0-) Vaults PKI engines ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to local network targets, potentially leading to information disclosure. Fixed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Vault
CVE-2026-3605 Apr 17, 2026
Vault Authenticated Deletion via Policy Globbing ( 2.0.0) An authenticated user with access to a kvv2 path through a policy containing a glob may be able to delete secrets they were not authorized to read or write, resulting in denial-of-service. This vulnerability did not allow a malicious user to delete secrets across namespaces, nor read any secret data. Fxed in Vault Community Edition 2.0.0 and Vault Enterprise 2.0.0, 1.21.5, 1.20.10, and 1.19.16.
Vault
CVE-2026-4660 Apr 09, 2026
HashiCorp go-getter v1.8.5 Arbitrary File Read via Git URL HashiCorps go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
CVE-2026-2808 Mar 11, 2026
HashiCorp Consul <1.21.10 vulnerable to arbitrary file read via K8s auth HashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are vulnerable to arbitrary file read when configured with Kubernetes authentication. This vulnerability, CVE-2026-2808, is fixed in Consul 1.18.21, 1.21.11 and 1.22.5.
Consul
CVE-2026-0969 Feb 12, 2026
Arbitrary Code Exec CVE-2026-0969 in next-mdx-remote <6.0.0 The serialize function used to compile MDX in next-mdx-remote is vulnerable to arbitrary code execution due to insufficient sanitization of MDX content. This vulnerability, CVE-2026-0969, is fixed in next-mdx-remote 6.0.0.
CVE-2025-13357 Nov 21, 2025
Vault Terraform Provider LDAP DenyNullBind FALSE default before v5.5.0 Vaults Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.
CVE-2025-13432 Nov 21, 2025
Terraform Enterprise state version privilege escalation (pre-1.1.1) Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise workspace. This may allow for the alteration of infrastructure if a subsequent plan operation is approved by a user with approval permission or auto-applied. This vulnerability, CVE-2025-13432, is fixed in Terraform Enterprise version 1.1.1 and 1.0.3.
Terraform Enterprise
CVE-2025-11374 Oct 28, 2025
Consul DoS via KV Endpoint CVE202511374 (Fixed in v1.22.0) Consul and Consul Enterprises (Consul) key/value endpoint is vulnerable to denial of service (DoS) due to incorrect Content Length header validation. This vulnerability, CVE-2025-11374, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Consul
CVE-2025-11375 Oct 28, 2025
Consul DoS via Unbounded Content-Length; V1.22.0+ Fixes Consul and Consul Enterprises (Consul) event endpoint is vulnerable to denial of service (DoS) due to lack of maximum value on the Content Length header. This vulnerability, CVE-2025-11375, is fixed in Consul Community Edition 1.22.0 and Consul Enterprise 1.22.0, 1.21.6, 1.20.8 and 1.18.12.
Consul
CVE-2025-12044 Oct 23, 2025
Vault CE 1.21.0 / Enterprise 1.21.0: JSON DOS (unauthenticated) Vault and Vault Enterprise (Vault) are vulnerable to an unauthenticated denial of service when processing JSON payloads. This occurs due to a regression from a previous fix for [+HCSEC-2025-24+|https://discuss.hashicorp.com/t/hcsec-2025-24-vault-denial-of-service-though-complex-json-payloads/76393]  which allowed for processing JSON payloads before applying rate limits. This vulnerability, CVE-2025-12044, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.16.27, 1.19.11, 1.20.5, and 1.21.0.
Vault
CVE-2025-11621 Oct 23, 2025
Vault AWS Auth Bypass (CVE-2025-11621) fixed 1.21.0/1.20.5/1.19.11/1.16.27 Vault and Vault Enterprises (Vault) AWS Auth method may be susceptible to authentication bypass if the role of the configured bound_principal_iam is the same across AWS accounts, or uses a wildcard. This vulnerability, CVE-2025-11621, is fixed in Vault Community Edition 1.21.0 and Vault Enterprise 1.21.0, 1.20.5, 1.19.11, and 1.16.27
Vault
CVE-2025-6203 Aug 28, 2025
Vault Memory Exhaustion via Large Payload (1.20.3+ Vulnerable) A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vaults auditing subroutine, potentially resulting in the Vault server to become unresponsive. This vulnerability, CVE-2025-6203, is fixed in Vault Community Edition 1.20.3 and Vault Enterprise 1.20.3, 1.19.9, 1.18.14, and 1.16.25.
Vault
CVE-2025-8959 Aug 15, 2025
HashiCorp go-getter 1.7.9: Symlink attack in subdirectory download HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.
Go Getter
CVE-2025-6013 Aug 06, 2025
Vault LDAP MFA Bypass via username_as_alias; fixed in CE 1.20.2 Vault and Vault Enterprises (Vault) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but with leading or trailing spaces. Fixed in Vault Community Edition 1.20.2 and Vault Enterprise 1.20.2, 1.19.8, 1.18.13, and 1.16.24.
Vault
CVE-2025-6011 Aug 01, 2025
Vault Userpass Auth Timing Side Channel Username Enumeration A timing side channel in Vault and Vault Enterprises (Vault) userpass auth method allowed an attacker to distinguish between existing and non-existing users, and potentially enumerate valid usernames for Vaults Userpass auth method. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Vault
CVE-2025-5999 Aug 01, 2025
Vault Privilege Escalation via Identity Endpoint (pre-1.20.0) A privileged Vault operator with write permissions to the root namespaces identity endpoint could escalate their own or another users token privileges to Vaults root policy. Fixed in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11 and 1.16.22.
Vault
CVE-2025-6004 Aug 01, 2025
Vault Userpass/LDAP Lockout Bypass before 1.20.1 Vault and Vault Enterprises (Vault) user lockout feature could be bypassed for Userpass and LDAP authentication methods. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.
Vault
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.