---
id: CVE-2025-54999
aliases:
  - GHSA-hh28-h22f-8357
  - BIT-openbao-2025-54999
  - GO-2025-3854
title: OpenBao has a Timing Side-Channel in the Userpass Auth Method
summary: OpenBao has a Timing Side-Channel in the Userpass Auth Method
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
vendor: openbao
product: github.com/openbao/openbao
ecosystem: go
affected:
  - 'github.com/openbao/openbao >= 0.1.0, < 2.3.2'
  - github.com/openbao/openbao < 0.0.0-20250806193356-4d9b5d3d6486
patched:
  - github.com/openbao/openbao 2.3.2
  - github.com/openbao/openbao 0.0.0-20250806193356-4d9b5d3d6486
published: '2025-08-08'
updated: '2026-07-27'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-hh28-h22f-8357'
references:
  - url: 'https://github.com/openbao/openbao/security/advisories/GHSA-hh28-h22f-8357'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54999'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6011'
  - url: >-
      https://github.com/openbao/openbao/commit/4d9b5d3d6486ab9fbd5b644173fa0097015d6626
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2025-15-timing-side-channel-in-vault-s-userpass-auth-method/76034
  - url: >-
      https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enumeration-in-userpass-auth-method/76095
  - url: 'https://github.com/openbao/openbao'
tags:
  - osv
  - go
epss: 0.00193
epssPercentile: 0.07998
ingestedAt: '2026-07-27T19:08:54.841Z'
---

## Overview

### Impact

When using OpenBao's `userpass` auth method, user enumeration was possible due to timing difference between non-existent users and users with stored credentials. This is independent of whether the supplied credentials were valid for the given user. 

### Patches

OpenBao v2.3.2 will patch this issue.

### Workarounds

Users may use another auth method or apply rate limiting quotas to limit the number of requests in a period of time: https://openbao.org/api-docs/system/rate-limit-quotas/

### References

This issue was disclosed to HashiCorp and is the OpenBao equivalent of the following tickets:

- https://discuss.hashicorp.com/t/hcsec-2025-15-timing-side-channel-in-vault-s-userpass-auth-method/76034
- https://nvd.nist.gov/vuln/detail/CVE-2025-6011

Barring further information, this is also assumed to cover and remediate the following additional vulnerability:

- https://discuss.hashicorp.com/t/hcsec-2025-21-vault-user-enumeration-in-userpass-auth-method/76095
- https://nvd.nist.gov/vuln/detail/CVE-2025-6010

If this is not the case as further details emerge, a new CVE will be assigned for remediating that. Otherwise, no further CVE will be sought.

## Affected packages

- `github.com/openbao/openbao >= 0.1.0, < 2.3.2`
- `github.com/openbao/openbao < 0.0.0-20250806193356-4d9b5d3d6486`

## Remediation

Upgrade to a patched release:

- `github.com/openbao/openbao 2.3.2`
- `github.com/openbao/openbao 0.0.0-20250806193356-4d9b5d3d6486`
