---
id: CVE-2025-13357
title: >-
  Vault’s Terraform Provider incorrectly set the default deny_null_bind
  parameter for the LDAP auth method to false by default, potentially resulting
  in an insecure configuration
summary: >-
  Vault’s Terraform Provider incorrectly set the default deny_null_bind
  parameter for the LDAP auth method to false by default, potentially resulting
  in an insecure configuration. If the underlying LDAP server allowed anonymous
  or unauthen…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1188
vendor: hashicorp
product: terraform_provider
affected:
  - 'terraform_provider >= 4.2.0, < 5.5.0'
patched:
  - terraform_provider 5.5.0
published: '2025-11-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T10:10:00.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13357'
references:
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2025-33-vault-terraform-provider-applied-incorrect-defaults-for-ldap-auth-method/76822
    label: security@hashicorp.com
tags:
  - nvd
epss: 0.0053
epssPercentile: 0.42982
ingestedAt: '2026-10-08T10:28:20.224Z'
---

## Overview

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.

## Affected

- `terraform_provider >= 4.2.0, < 5.5.0`

## Remediation

Upgrade past the affected range:

- `terraform_provider 5.5.0`
