<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Hashicorp Vault (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/hashicorp-vault.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/hashicorp-vault-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Hashicorp Vault (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:55 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-68476 – KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68476</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68476</strong></p>
  <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token spe…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6337 – HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6337</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6337</guid>
    <pubDate>Fri, 08 Dec 2023 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6337</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.  Fixed in Vault 1.15.4, 1.14.8, 1.13.12.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6337">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-33001 – Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33001</guid>
    <pubDate>Tue, 16 May 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-33001</strong></p>
  <p>Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-40186 – An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40186</guid>
    <pubDate>Thu, 22 Sep 2022 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-40186</strong></p>
  <p>An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an issue with checking the proper alias assigned to an entity. This may allow for unintended access to key/value paths usin…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36129 – HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters usin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36129</guid>
    <pubDate>Tue, 26 Jul 2022 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36129</strong></p>
  <p>HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or catastrophic failure. Fixed in Vault Enterprise 1.9.8, 1.10.5, and 1.11.1.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43837 – vault-cli is a configurable command-line interface tool (and python library) to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43837</guid>
    <pubDate>Thu, 16 Dec 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43837</strong></p>
  <p>vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest of the contents of the secret as a Jinja2 template. Jinja2 is a powerful templating engine and is not designed to safel…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-42135 – HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-42135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-42135</guid>
    <pubDate>Mon, 11 Oct 2021 03:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-42135</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.8.x through 1.8.4 may have an unexpected interaction between glob-related policies and the Google Cloud secrets engine. Users may, in some situations, have more privileges than intended, e.g., a user with read permission for the /gcp/roleset/* path may be able to issue Google Cloud service account credentials.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32923 – HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32923</guid>
    <pubDate>Thu, 03 Jun 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32923</strong></p>
  <p>HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32074 – HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32074</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32074</guid>
    <pubDate>Fri, 07 May 2021 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32074</strong></p>
  <p>HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line secret was not correctly registered with GitHub Actions for log masking.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32074">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29653 – HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstance...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29653</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29653</guid>
    <pubDate>Thu, 22 Apr 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29653</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired certificates from the CRL. Fixed in 1.5.8, 1.6.4, and 1.7.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29653">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-27400 – HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27400</guid>
    <pubDate>Thu, 22 Apr 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-27400</strong></p>
  <p>HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not validate TLS certificates when connecting to Cassandra clusters. Fixed in 1.6.4 and 1.7.1</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3282 – HashiCorp Vault Enterprise 1.6.0 &amp; 1.6.1 allowed the `remove-peer` raft operator...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3282</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3282</strong></p>
  <p>HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secondaries without authentication. Fixed in 1.6.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16251 – HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16251</guid>
    <pubDate>Wed, 26 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16251</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.8.3 and newer, when configured with the GCP GCE auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16250 – HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16250</guid>
    <pubDate>Wed, 26 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16250</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4.4, and 1.5.1..</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24359 – HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24359</guid>
    <pubDate>Thu, 20 Aug 2020 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24359</strong></p>
  <p>HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13223 – HashiCorp Vault and Vault Enterprise logged proxy environment variables that pot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13223</guid>
    <pubDate>Wed, 10 Jun 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13223</strong></p>
  <p>HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-12757 – HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12757</guid>
    <pubDate>Wed, 10 Jun 2020 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-12757</strong></p>
  <p>HashiCorp Vault and Vault Enterprise 1.4.0 and 1.4.1, when configured with the GCP Secrets Engine, may incorrectly generate GCP Credentials with the default time-to-live lease duration instead of the engine-configured setting. This may lead to generated GCP credentials being valid for longer than intended. Fixed in 1.4.2.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10661 – HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under ce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10661</guid>
    <pubDate>Mon, 23 Mar 2020 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10661</strong></p>
  <p>HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7220 – HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7220</guid>
    <pubDate>Thu, 23 Jan 2020 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7220</strong></p>
  <p>HashiCorp Vault Enterprise 0.11.0 through 1.3.1 fails, in certain circumstances, to revoke dynamic secrets for a mount in a deleted namespace. Fixed in 1.3.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19786 – HashiCorp Vault before 1.0.0 writes the master key to the server log in certain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19786</guid>
    <pubDate>Wed, 05 Dec 2018 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19786</strong></p>
  <p>HashiCorp Vault before 1.0.0 writes the master key to the server log in certain unusual or misconfigured scenarios in which incorrect data comes from the autoseal mechanism without an error being reported.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19786">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
