github.com/openbao/openbao vulnerabilities
CVEs whose affected-version data names the github.com/openbao/openbao package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
25 CVEsRSS
CVE-2026-45808HighOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying cred…
CVE-2026-46358MediumOpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …
CVE-2026-46405Medium· 5.3OpenBao is an open source identity-based secrets management system
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `log…
CVE-2026-42186LowOpenBao's Namespace Deletion May Not Delete Data Properly
OpenBao's Namespace Deletion May Not Delete Data Properly
CVE-2026-39396Low· 3.1OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
CVE-2026-40264LowOpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
CVE-2026-39388Low· 3.1OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
CVE-2026-39946Medium· 4.9OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBao's SQL Injection in PostgreSQL database secrets engine
CVE-2026-33758CriticalOpenBao has Reflected XSS in its OIDC authentication error message
OpenBao has Reflected XSS in its OIDC authentication error message
CVE-2026-33757Critical· 9.6OpenBao lacks user confirmation for OIDC direct callback mode
OpenBao lacks user confirmation for OIDC direct callback mode
CVE-2025-64761HighOpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
CVE-2025-62705MediumOpenBao and Vault Leak []byte Fields in Audit Logs
OpenBao and Vault Leak []byte Fields in Audit Logs
CVE-2025-62513MediumOpenBao leaks HTTPRawBody in Audit Logs
OpenBao leaks HTTPRawBody in Audit Logs
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2025-54996High· 7.2OpenBao Root Namespace Operator May Elevate Token Privileges
OpenBao Root Namespace Operator May Elevate Token Privileges
CVE-2025-55003Medium· 5.7OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
CVE-2025-54998Medium· 5.3OpenBao Userpass and LDAP User Lockout Bypass
OpenBao Userpass and LDAP User Lockout Bypass
CVE-2025-54999Low· 3.7OpenBao has a Timing Side-Channel in the Userpass Auth Method
OpenBao has a Timing Side-Channel in the Userpass Auth Method
CVE-2025-55000Medium· 6.5OpenBao TOTP Secrets Engine Code Reuse
OpenBao TOTP Secrets Engine Code Reuse
CVE-2025-55001Medium· 6.5OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
CVE-2025-52894MediumOpenBao allows cancellation of root rekey and recovery rekey operations without authentication
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
CVE-2024-8185High· 7.5Hashicorp Vault vulnerable to denial of service through memory exhaustion
Hashicorp Vault vulnerable to denial of service through memory exhaustion
CVE-2024-9180High· 7.2Vault Community Edition privilege escalation vulnerability
Vault Community Edition privilege escalation vulnerability
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default