|
HCSEC-2026-32 - Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Policy Paths
|
|
0
|
91
|
August 24, 2026
|
|
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
|
|
0
|
585
|
August 13, 2026
|
|
HCSEC-2026-27 - Vault Enterprise vulnerable to cross-namespace entity deletion
|
|
0
|
417
|
August 10, 2026
|
|
HCSEC-2026-26 - Vault vulnerable to LIST authorization bypass via trailing-slash strip
|
|
0
|
249
|
August 10, 2026
|
|
HCSEC-2026-16 - Vault Audit Device Plugin Directory Guard Bypass via Legacy Path Option
|
|
0
|
337
|
July 1, 2026
|
|
HCSEC-2026-08 - Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations
|
|
0
|
1007
|
April 17, 2026
|
|
HCSEC-2026-07 - Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization
|
|
0
|
753
|
April 17, 2026
|
|
HCSEC-2026-06 - Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS
|
|
0
|
740
|
April 17, 2026
|
|
HCSEC-2026-05 - Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service
|
|
0
|
1011
|
April 17, 2026
|
|
HCSEC-2025-21 - Vault User Enumeration in Userpass Auth Method
|
|
1
|
1895
|
February 13, 2026
|
|
HCSEC-2025-33 - Vault Terraform Provider Applied Incorrect Defaults for LDAP Auth Method
|
|
0
|
1475
|
November 21, 2025
|
|
HCSEC-2025-32 - Incomplete Fix For Previous Vault DoS Issue
|
|
0
|
547
|
October 23, 2025
|
|
HCSEC-2025-31- Vault Vulnerable to Denial of Service Due to Rate Limit Regression
|
|
0
|
1997
|
October 23, 2025
|
|
HCSEC-2025-30 - Vault AWS Auth Method Authentication Bypass Through Mishandling of Cache Entries
|
|
0
|
1742
|
October 23, 2025
|
|
HCSEC-2025-24 - Vault Denial of Service Though Complex JSON Payloads
|
|
0
|
2800
|
August 28, 2025
|
|
HCSEC-2025-13 - Vault Root Namespace Operator May Elevate Token Privileges
|
|
0
|
2448
|
August 1, 2025
|
|
HCSEC-2025-22 - Multiple Vulnerabilities Impacting HashiCorp Vault and Vault Enterprise
|
|
0
|
6034
|
August 6, 2025
|
|
HCSEC-2025-20 - Vault LDAP MFA Enforcement Bypass When Using Username As Alias
|
|
0
|
2092
|
August 6, 2025
|
|
HCSEC-2025-17 - Vault TOTP Secrets Engine Code Reuse
|
|
0
|
1531
|
August 1, 2025
|
|
HCSEC-2025-19 - Vault Login MFA Bypass of Rate Limiting and TOTP Token Reuse
|
|
0
|
1498
|
August 1, 2025
|
|
HCSEC-2025-18 - Vault Certificate Auth Method Did Not Validate Common Name For Non-CA Certificates
|
|
0
|
1502
|
August 1, 2025
|
|
HCSEC-2025-16 - Vault Userpass and LDAP User Lockout Bypass
|
|
0
|
1753
|
August 1, 2025
|
|
HCSEC-2025-15 - Timing Side-Channel in Vault’s Userpass Auth Method
|
|
0
|
1530
|
August 1, 2025
|
|
HCSEC-2025-14 - Privileged Vault Operator May Execute Code on the Underlying Host
|
|
0
|
5592
|
August 1, 2025
|
|
HCSEC-2025-11 Vault Vulnerable to Recovery Key Cancellation Denial of Service
|
|
0
|
1346
|
June 25, 2025
|
|
HCSEC-2025-09 - Vault May Expose Sensitive Information in Error Logs When Processing Malformed Data With the KV v2 Plugin
|
|
0
|
2447
|
May 2, 2025
|
|
HCSEC-2025-07 - Vault’s Azure Authentication Method bound_location Restriction Could be Bypassed on Login
|
|
0
|
1066
|
May 2, 2025
|
|
HCSEC-2024-26 - Vault Vulnerable to Denial of Service Through Memory Exhaustion When Processing Raft Cluster Join Requests
|
|
0
|
1825
|
October 31, 2024
|
|
HCSEC-2024-21 - Vault Operators in Root Namespace May Elevate Their Privileges
|
|
0
|
3228
|
October 10, 2024
|
|
HCSEC-2024-20 - Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
|
|
0
|
2586
|
September 26, 2024
|