VendorsHashiCorpvaultall versions
Vulnerabilities

HashiCorp Vault

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

72CVEs
CVE-2025-6037
Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates
Published 2025-08-01 · Analyzed
6.8EPSS 0.002
CVE-2023-0620
Vault Vulnerable to SQL Injection When Configuring the Microsoft SQL Database Storage Backend
Published 2023-03-30 · Modified
6.7EPSS 0.004
CVE-2021-43998
HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-created entity alias if multiple entity aliases exist for a specified entity and mount combination, potentially resulting in incorrect policy enforcement. Fixed in Vault and Vault Enterprise 1.7.6, 1.8.5, and 1.9.0.
Published 2021-11-30 · Modified
6.5EPSS 0.010
CVE-2022-25244
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenization key configuration endpoint to authorized operators with `read` permissions on this endpoint. Fixed in Vault Enterprise 1.9.4, 1.8.9 and 1.7.10.
Published 2022-03-07 · Modified
6.5EPSS 0.010
CVE-2024-0831
Vault May Expose Sensitive Information When Configuring An Audit Log Device
Published 2024-02-01 · Modified
6.5EPSS 0.008
CVE-2022-25243
"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations to issue wildcard certificates to authorized users for a specified domain, even if the PKI role policy attribute allow_subdomains is set to false. Fixed in Vault Enterprise 1.8.9 and 1.9.4.
Published 2022-03-07 · Modified
6.5EPSS 0.006
CVE-2024-8365
Vault Leaks AppRole Client Tokens And Accessor in Audit Log
Published 2024-09-02 · Analyzed
6.5EPSS 0.005
CVE-2025-4166
Vault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin
Published 2025-05-02 · Analyzed
6.5EPSS 0.004
CVE-2025-6014
Vault TOTP Secrets Engine Code Reuse
Published 2025-08-01 · Analyzed
6.5EPSS 0.004
CVE-2023-0665
Vault PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata
Published 2023-03-30 · Modified
6.5EPSS 0.003
CVE-2025-6015
Vault Login MFA Bypass of Rate Limiting and TOTP Code Reuse
Published 2025-08-01 · Analyzed
5.7EPSS 0.003
CVE-2021-41802
HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID sharing a mount accessor with another user to acquire this other user’s policies by merging their identities. Fixed in Vault and Vault Enterprise 1.7.5 and 1.8.4.
Published 2021-10-08 · Modified
5.5EPSS 0.006
CVE-2024-2877
Vault Enterprise Leaks Sensitive HTTP Request Headers in the Audit Log When Deployed With a Performance Standby Node
Published 2024-04-30 · Analyzed
5.5EPSS 0.002
CVE-2023-2121
Vault’s KV Diff Viewer Allowed for HTML Injection
Published 2023-06-09 · Modified
5.4EPSS 0.004
CVE-2021-3024
HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid, unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Published 2021-02-01 · Modified
5.3EPSS 0.014
CVE-2020-25594
HashiCorp Vault and Vault Enterprise allowed for enumeration of Secrets Engine mount paths via unauthenticated HTTP requests. Fixed in 1.6.2 & 1.5.7.
Published 2021-02-01 · Modified
5.3EPSS 0.014
CVE-2020-35177
HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.
Published 2020-12-17 · Modified
5.3EPSS 0.013
CVE-2022-30689
HashiCorp Vault and Vault Enterprise from 1.10.0 to 1.10.2 did not correctly configure and enforce MFA on login after server restarts. This affects the Login MFA feature introduced in Vault and Vault Enterprise 1.10.0 and does not affect the separate Enterprise MFA feature set. Fixed in 1.10.3.
Published 2022-05-17 · Modified
5.3EPSS 0.012
CVE-2021-27668
HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.
Published 2021-08-31 · Modified
5.3EPSS 0.010
CVE-2021-38554
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
Published 2021-08-13 · Modified
5.3EPSS 0.009
CVE-2020-35453
HashiCorp Vault Enterprise’s Sentinel EGP policy feature incorrectly allowed requests to be processed in parent and sibling namespaces. Fixed in 1.5.6 and 1.6.1.
Published 2020-12-17 · Modified
5.3EPSS 0.008
CVE-2020-10660
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
Published 2020-03-23 · Modified
5.3EPSS 0.008
CVE-2023-3462
Vault's LDAP Auth Method Allows for User Enumeration
Published 2023-07-31 · Modified
5.3EPSS 0.006
CVE-2022-41316
HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL issued by the role's CA into memory on startup, resulting in the revocation list not being checked if the CRL has not yet been retrieved. Fixed in 1.12.0, 1.11.4, 1.10.7, and 1.9.10.
Published 2022-10-12 · Modified
5.3EPSS 0.004
CVE-2025-6004
Vault Userpass and LDAP User Lockout Bypass
Published 2025-08-01 · Analyzed
5.3EPSS 0.004
CVE-2023-25000
Vault Vulnerable to Cache-Timing Attacks During Seal and Unseal Operations
Published 2023-03-30 · Modified
5.0EPSS 0.002
CVE-2023-3774
Vault Enterprise Namespace Creation May Lead to Denial of Service
Published 2023-07-28 · Modified
4.9EPSS 0.007
CVE-2023-3775
Vault Enterprise's Sentinel RGP Policies Allowed For Cross-Namespace Denial of Service
Published 2023-09-28 · Modified
4.9EPSS 0.005
CVE-2021-38553
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
Published 2021-08-13 · Modified
4.4EPSS 0.003
CVE-2025-6011
Timing Side-Channel in Vault’s Userpass Auth Method
Published 2025-08-01 · Analyzed
3.7EPSS 0.003
CVE-2025-4656
Vault Vulnerable to Recovery Key Cancellation Denial of Service
Published 2025-06-25 · Analyzed
3.1EPSS 0.002
CVE-2023-2197
Vault Enterprise Vulnerable to Padding Oracle Attacks When Using a CBC-based Encryption Mechanism with a HSM
Published 2023-05-01 · Modified
2.5EPSS 0.001
← Prev2 / 2