---
id: CVE-2021-32923
title: 'vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)'
summary: >-
  A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could
  allow a remote attacker to bypass security restrictions caused by a renewal
  logic flaw when a token lease or dynamic secret lease was renewed inside the
  last sec…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'
cvssSource: vendor
cwe: CWE-613
vendor: Red Hat
product: Red Hat Openshift Container Storage 4
affected:
  - openshift_container_storage 4
patched:
  - github.com/hashicorp/vault 1.7.2
  - github.com/hashicorp/vault 1.6.5
  - github.com/hashicorp/vault 1.5.9
published: '2021-06-03'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T14:01:27+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json
  - url: 'https://access.redhat.com/security/cve/CVE-2021-32923'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1968032'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2021-32923'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-32923'
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2021-15-vault-renewed-nearly-expired-leases-with-incorrect-non-expiring-ttls/24603
  - url: 'https://security.gentoo.org/glsa/202207-01'
  - url: 'https://www.hashicorp.com/blog/category/vault'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.01376
epssPercentile: 0.70888
aliases:
  - GHSA-38j9-7pp9-2hjw
  - BIT-vault-2021-32923
  - GO-2022-0623
ecosystem: go
scores:
  vendor: 6.5
  osv: 7.4
ingestedAt: '2026-09-12T03:13:01.748Z'
---

## Overview

A flaw was found in the HashiCorp Vault and Vault Enterprise. The vault could allow a remote attacker to bypass security restrictions caused by a renewal logic flaw when a token lease or dynamic secret lease was renewed inside the last second of its maximum TTL. By sending a specially crafted request, an attacker can bypass authentication validation and gain access to the system.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Openshift Container Storage 4 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-32923.json)

**vault: Token leases incorrectly treated as non-expiring** — rated Moderate by Red Hat. Released 2021-06-03, updated 2026-09-17.

Affected:

- Red Hat Openshift Container Storage 4

Not affected:

- Logging Subsystem for Red Hat OpenShift
- OpenShift Service Mesh 2.0
- Red Hat Advanced Cluster Management for Kubernetes 2
- Red Hat OpenShift Container Platform 4
- Red Hat Openshift Data Foundation 4

## Remediation

Refer to the advisory for fix availability.

## Package advisory (CVE-2021-32923)

Affected packages:

- `github.com/hashicorp/vault >= 1.7.0, < 1.7.2`
- `github.com/hashicorp/vault >= 1.6.0, < 1.6.5`
- `github.com/hashicorp/vault >= 0.10.0, < 1.5.9`

Patched in:

- `github.com/hashicorp/vault 1.7.2`
- `github.com/hashicorp/vault 1.6.5`
- `github.com/hashicorp/vault 1.5.9`

Source: https://osv.dev/vulnerability/GHSA-38j9-7pp9-2hjw
