Where
-Infinity
0

HashiCorp VaultAudit Log Plugin Directory Guard Bypass via Legacy path Option

Risk 26
Severity
4.4
First published (updated )

HashiCorp VaultIf a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorizati…

Risk 33
Severity
7
First published (updated )

HashiCorp Vault Community EditionAn authenticated user with access to a kvv2 path through a policy containing a glob may be able to d…

Risk 33
Severity
7
First published (updated )

HashiCorp VaultVault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations

Risk 31
Severity
7.5
EPSS
0.02%
First published (updated )

HashiCorp VaultVault Token Leaked to Backends via Authorization: Bearer Passthrough Header

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

HashiCorp VaultVault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS

Risk 34
Severity
8.6
EPSS
0.01%
First published (updated )

HashiCorp VaultVault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service

Risk 60
Severity
8.1
First published (updated )

HashiCorp Vault 2.0End of life details

First published (updated )

HashiCorp VaultVault Vulnerable to Denial of Service Due to Rate Limit Regression

Risk 43
Severity
7.5
First published (updated )

HashiCorp VaultVault AWS auth method bypass due to AWS client cache

Risk 60
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

HashiCorp Vault 1.21Reached end of life

EOL
Apr 13, 2026
First published (updated )

HashiCorp VaultVault unauthenticated denial of service through complex json payload

Risk 43
Severity
7.5
First published (updated )

HashiCorp VaultVault LDAP MFA Enforcement Bypass When Using Username As Alias

Risk 60
Severity
8.1
First published (updated )

HashiCorp VaultVault Login MFA Bypass of Rate Limiting and TOTP Code Reuse

Risk 33
Severity
5.7
First published (updated )

HashiCorp VaultTiming Side-Channel in Vault’s Userpass Auth Method

Risk 20
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

HashiCorp VaultVault Userpass and LDAP User Lockout Bypass

Risk 27
Severity
5.3
First published (updated )

HashiCorp VaultVault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates

Risk 61
Severity
6.8
First published (updated )

HashiCorp VaultVault TOTP Secrets Engine Code Reuse

Risk 38
Severity
6.5
First published (updated )

HashiCorp VaultArbitrary Remote Code Execution via Plugin Catalog Abuse

Risk 72
Severity
9.1
First published (updated )

HashiCorp VaultVault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

HashiCorp VaultVault May Include Sensitive Data in Error Logs When Using the KV v2 Plugin

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

HashiCorp Vault 1.18Reached end of life

EOL
Mar 4, 2025
First published (updated )

HashiCorp Vault 1.18Reached end of life

EOL
Mar 4, 2025
First published (updated )

HashiCorp VaultVault Operators in Root Namespace May Elevate Their Privileges

Risk 51
Severity
7.2
EPSS
0.05%
First published (updated )

HashiCorp VaultVault Leaks AppRole Client Tokens And Accessor in Audit Log

Risk 28
Severity
6.5
EPSS
0.09%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

HashiCorp Vault 1.17Reached end of life

EOL
Oct 9, 2024
First published (updated )

HashiCorp Vault 1.17Reached end of life

EOL
Oct 9, 2024
First published (updated )

HashiCorp VaultVault Vulnerable to Denial of Service When Setting a Proxy Protocol Behavior

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

HashiCorp VaultVault Incorrectly Validated JSON Web Tokens (JWT) Audience Claims

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

HashiCorp Vault 1.16Reached end of life

EOL
Jun 10, 2024
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203