VulnSea

openbao vulnerabilities

CVEs whose affected-version data names the openbao package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

Twilightopenbao · openbaoEPSS 0.45%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

Sunlitopenbao · openbaoEPSS 0.44%via NVD
CVE-2026-55775Low· 2.3⚖ disputed
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…

Sunlitopenbao · openbaoEPSS 0.36%via NVD
CVE-2026-55776Medium· 6.5PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

Twilightopenbao · openbaoEPSS 0.46%via NVD
openbao vulnerabilities (CVEs) · VulnSea