VendorsHashiCorpvaultall versions
Vulnerabilities

HashiCorp Vault

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2020-35192
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Published 2020-12-17 · Modified
10.0EPSS 0.029
CVE-2020-12757
HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.
Published 2020-06-10 · Modified
9.8EPSS 0.015
CVE-2024-2048
Vault Cert Auth Method Did Not Correctly Validate Non-CA Certificates
Published 2024-03-04 · Analyzed
9.8EPSS 0.004
CVE-2022-36129
HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.
Published 2022-07-26 · Modified
9.1EPSS 0.016
CVE-2020-10661
HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.
Published 2020-03-23 · Modified
9.1EPSS 0.011
CVE-2022-40186
An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths using that metadata in Vault.
Published 2022-09-22 · Modified
9.1EPSS 0.010
CVE-2025-6000
Arbitrary Remote Code Execution via Plugin Catalog Abuse
Published 2025-08-01 · Analyzed
9.1EPSS 0.009
CVE-2026-4525
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
Published 2026-04-17 · Modified
8.8EPSS 0.006
CVE-2025-3879
Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login
Published 2025-05-02 · Analyzed
8.8EPSS 0.004
CVE-2024-7594
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Published 2024-09-26 · Analyzed
8.8EPSS 0.003
CVE-2026-5052
Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
Published 2026-04-17 · Analyzed
8.6EPSS 0.004
CVE-2020-16251
HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.
Published 2020-08-26 · Modified
8.2EPSS 0.028
CVE-2020-16250
HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..
Published 2020-08-26 · Modified
8.2EPSS 0.015
CVE-2018-19786
HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.
Published 2018-12-05 · Modified
8.1EPSS 0.009
CVE-2021-42135
HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.
Published 2021-10-11 · Modified
8.1EPSS 0.008
CVE-2023-24999
Vault Fails to Verify if the AppRole SecretID Belongs to Role During a Destroy Operation
Published 2023-03-10 · Modified
8.1EPSS 0.006
CVE-2026-3605
Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
Published 2026-04-17 · Modified
8.1EPSS 0.005
CVE-2025-6013
Vault LDAP MFA Enforcement Bypass When Using Username As Alias
Published 2025-08-06 · Analyzed
8.1EPSS 0.005
CVE-2025-11621
Vault AWS auth method bypass due to AWS client cache
Published 2025-10-23 · Analyzed
8.1EPSS 0.005
CVE-2023-5077
Vault's Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets
Published 2023-09-28 · Modified
7.6EPSS 0.004
CVE-2020-7220
HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.
Published 2020-01-23 · Modified
7.5EPSS 0.014
CVE-2021-3282
HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.
Published 2021-02-01 · Modified
7.5EPSS 0.013
CVE-2020-13223
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.
Published 2020-06-10 · Modified
7.5EPSS 0.012
CVE-2026-5807
Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
Published 2026-04-17 · Modified
7.5EPSS 0.009
CVE-2023-6337
Vault May be Vulnerable to a Denial of Service Through Memory Exhaustion When Handling Large HTTP Requests
Published 2023-12-08 · Modified
7.5EPSS 0.008
CVE-2023-5954
Vault Requests Triggering Policy Checks May Lead To Unbounded Memory Consumption
Published 2023-11-09 · Modified
7.5EPSS 0.007
CVE-2025-6203
Vault unauthenticated denial of service through complex json payload
Published 2025-08-28 · Analyzed
7.5EPSS 0.007
CVE-2021-27400
HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1
Published 2021-04-22 · Modified
7.5EPSS 0.006
CVE-2021-29653
HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.
Published 2021-04-22 · Modified
7.5EPSS 0.006
CVE-2025-12044
Vault Vulnerable to Denial of Service Due to Rate Limit Regression
Published 2025-10-23 · Analyzed
7.5EPSS 0.005
CVE-2024-6468
Vault Vulnerable to Denial of Service When Setting a Proxy Protocol Behavior
Published 2024-07-11 · Analyzed
7.5EPSS 0.005
CVE-2024-8185
Vault Vulnerable to Denial of Service When Processing Raft Join Requests
Published 2024-10-31 · Analyzed
7.5EPSS 0.005
CVE-2024-5798
Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
Published 2024-06-12 · Modified
7.5EPSS 0.003
CVE-2021-32923
HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.
Published 2021-06-03 · Modified
7.4EPSS 0.014
CVE-2024-9180
Vault Operators in Root Namespace May Elevate Their Privileges
Published 2024-10-10 · Analyzed
7.2EPSS 0.005
CVE-2025-5999
Vault Root Namespace Operator May Elevate Token Privileges
Published 2025-08-01 · Analyzed
7.2EPSS 0.005
CVE-2021-45042
In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Integrated Storage backend allowed an authenticated user (with write permissions to a kv secrets engine) to cause a panic and denial of service of the storage backend. The earliest affected version is 1.4.0.
Published 2021-12-17 · Modified
6.8EPSS 0.014
CVE-2020-25816
HashiCorp Vault and Vault Enterprise versions 1.0 and newer allowed leases created with a batch token to outlive their TTL because expiration time was not scheduled correctly. Fixed in 1.4.7 and 1.5.4.
Published 2020-09-30 · Modified
6.8EPSS 0.010
CVE-2023-4680
Vault's Transit Secrets Engine Allowed Nonce Specified without Convergent Encryption
Published 2023-09-14 · Modified
6.8EPSS 0.004
CVE-2024-2660
Vault TLS Cert Auth Method Did Not Correctly Validate OCSP Responses
Published 2024-04-04 · Analyzed
6.8EPSS 0.003
1 / 2Next →