CVE-2024-8185High· 7.5▾ TwilightHashicorp Vault vulnerable to denial of service through memory exhaustion
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 27.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint. An attacker may send a large volume of requests to the endpoint which may cause Vault to consume excessive system memory resources, potentially leading to a crash of the underlying system and the Vault process itself.
This vulnerability, CVE-2024-8185, is fixed in Vault Community 1.18.1 and Vault Enterprise 1.18.1, 1.17.8, and 1.16.12.
github.com/hashicorp/vault >= 1.2.0, < 1.18.1github.com/openbao/openbao < 2.0.3Upgrade to a patched release:
github.com/hashicorp/vault 1.18.1github.com/openbao/openbao 2.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability