github.com/hashicorp/vault vulnerabilities
CVEs whose affected-version data names the github.com/hashicorp/vault package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-5052Medium· 5.3HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
CVE-2026-5807High· 7.5HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
CVE-2026-4525High· 7.5HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-5999High· 7.2Hashicorp Vault has Privilege Escalation Vulnerability
Hashicorp Vault has Privilege Escalation Vulnerability
CVE-2025-6037Medium· 6.8Hashicorp Vault has Incorrect Validation for Non-CA Certificates
Hashicorp Vault has Incorrect Validation for Non-CA Certificates
CVE-2025-4166Medium· 4.5Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
CVE-2024-6468High· 7.5Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
Hashicorp Vault vulnerable to Improper Check or Handling of Exceptional Conditions
CVE-2024-5798Low· 2.6HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
HashiCorp Vault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims
CVE-2023-5954High· 7.5HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability
CVE-2023-5077High· 7.6Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-4680Medium· 6.8HashiCorp Vault Improper Input Validation vulnerability
HashiCorp Vault Improper Input Validation vulnerability