CVE-2021-38554Medium· 5.3▾ SunlitA flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.9%
Last analysed / modified upstream
A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the previous authenticated user’s cached secrets, even if they were not authorized by Vault policies to view them.
vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser — rated Low by Red Hat. Released 2021-08-13, updated 2026-09-17.
Affected:
No fix planned:
Not affected:
Out of support scope
Affected packages:
github.com/hashicorp/vault < 1.6.6github.com/hashicorp/vault >= 1.7.0, < 1.7.4Patched in:
github.com/hashicorp/vault 1.6.6github.com/hashicorp/vault 1.7.4Connected by shared product, vendor, weakness, or advisory.
CVE-2021-32923Medium· 6.5vault: Token leases incorrectly treated as non-expiring (CVE-2021-32923)
CVE-2025-22866Medium· 5.3crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
CVE-2026-10051Medium· 5.3jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)
CVE-2025-2842Medium· 4.3A flaw was found in the Tempo Operator
CVE-2025-2786Medium· 4.3A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance
CVE-2026-80110High· 8.1A flaw was found in pki-core