{"schema_version":1,"title":"github.com/hashicorp/vault (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 55 vulnerabilities in github.com/hashicorp/vault (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-5052, was published on 17 April 2026.","url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault","json_url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-hashicorp-vault","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":55,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":6},"latest":[{"cve":"CVE-2026-5052","cvss":5.3,"epss":0.0039,"slug":"cve-2026-5052-hashicorp-vault-ssrf-in-pki-engine-acme-validation","title":"HashiCorp Vault SSRF in PKI engine ACME validation","severity":"medium","exploited":false,"published_at":"2026-04-17T06:31:07+00:00","url":"https://junglewise.ai/threats/cve-2026-5052-hashicorp-vault-ssrf-in-pki-engine-acme-validation"},{"cve":"CVE-2026-5807","cvss":7.5,"epss":0.0091,"slug":"cve-2026-5807-hashicorp-vault-denial-of-service-in-root-token-generation-and","title":"HashiCorp Vault denial of service in root token generation and rekeying","severity":"high","exploited":false,"published_at":"2026-04-17T05:16:19.303+00:00","url":"https://junglewise.ai/threats/cve-2026-5807-hashicorp-vault-denial-of-service-in-root-token-generation-and"},{"cve":"CVE-2026-4525","cvss":7.5,"epss":0.0059,"slug":"cve-2026-4525-hashicorp-vault-token-disclosure-in-auth-plugin-header-forwarding","title":"HashiCorp Vault token disclosure in auth plugin header forwarding","severity":"high","exploited":false,"published_at":"2026-04-17T04:16:09.997+00:00","url":"https://junglewise.ai/threats/cve-2026-4525-hashicorp-vault-token-disclosure-in-auth-plugin-header-forwarding"},{"cve":"CVE-2026-3605","cvss":8.1,"epss":0.005,"slug":"cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine","title":"HashiCorp Vault policy bypass in KVv2 secrets engine","severity":"high","exploited":false,"published_at":"2026-04-17T04:16:03.263+00:00","url":"https://junglewise.ai/threats/cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine"},{"cve":"CVE-2025-11621","cvss":3.1,"epss":0.0049,"slug":"cve-2025-11621-hashicorp-vault-and-vault-enterprise-s-aws-auth-method-may-be","title":"GO-2025-4070 - HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-10-30T15:02:33+00:00","url":"https://junglewise.ai/threats/cve-2025-11621-hashicorp-vault-and-vault-enterprise-s-aws-auth-method-may-be"},{"cve":"CVE-2025-12044","cvss":3.1,"epss":0.0053,"slug":"cve-2025-12044-hashicorp-vault-and-vault-enterprise-vulnerable-to-a-denial-of","title":"GO-2025-4071 - Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-10-30T15:02:33+00:00","url":"https://junglewise.ai/threats/cve-2025-12044-hashicorp-vault-and-vault-enterprise-vulnerable-to-a-denial-of"},{"cve":"CVE-2025-6203","cvss":3.1,"epss":0.007,"slug":"cve-2025-6203-hashicorp-vault-community-edition-denial-of-service-though-complex","title":"GO-2025-3924 - HashiCorp Vault Community Edition Denial of Service Though Complex JSON Payloads in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-09-08T14:13:10+00:00","url":"https://junglewise.ai/threats/cve-2025-6203-hashicorp-vault-community-edition-denial-of-service-though-complex"},{"cve":"CVE-2025-5999","cvss":3.1,"epss":0.0051,"slug":"cve-2025-5999-hashicorp-vault-has-privilege-escalation-vulnerability","title":"GO-2025-3837 - Hashicorp Vault has Privilege Escalation Vulnerability in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-5999-hashicorp-vault-has-privilege-escalation-vulnerability"},{"cve":"CVE-2025-6037","cvss":3.1,"epss":0.0025,"slug":"cve-2025-6037-hashicorp-vault-has-incorrect-validation-for-non-ca-certificates","title":"GO-2025-3836 - Hashicorp Vault has Incorrect Validation for Non-CA Certificates in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6037-hashicorp-vault-has-incorrect-validation-for-non-ca-certificates"},{"cve":"CVE-2025-6015","cvss":3.1,"epss":0.0033,"slug":"cve-2025-6015-hashicorp-vault-has-login-mfa-rate-limit-bypass-vulnerability","title":"GO-2025-3842 - Hashicorp Vault has Login MFA Rate Limit Bypass Vulnerability in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6015-hashicorp-vault-has-login-mfa-rate-limit-bypass-vulnerability"},{"cve":"CVE-2025-6004","cvss":3.1,"epss":0.0041,"slug":"cve-2025-6004-hashicorp-vault-has-lockout-feature-authentication-bypass","title":"GO-2025-3840 - Hashicorp Vault has Lockout Feature Authentication Bypass in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6004-hashicorp-vault-has-lockout-feature-authentication-bypass"},{"cve":"CVE-2025-6014","cvss":3.1,"epss":0.0039,"slug":"cve-2025-6014-hashicorp-vault-s-totp-secrets-engine-susceptible-to-code-reuse","title":"GO-2025-3841 - Hashicorp Vault's TOTP Secrets Engine Susceptible to Code Reuse in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6014-hashicorp-vault-s-totp-secrets-engine-susceptible-to-code-reuse"},{"cve":"CVE-2025-6000","cvss":3.1,"epss":0.0091,"slug":"cve-2025-6000-hashicorp-vault-has-code-execution-vulnerability-via-plugin","title":"GO-2025-3838 - Hashicorp Vault has Code Execution Vulnerability via Plugin Configuration in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6000-hashicorp-vault-has-code-execution-vulnerability-via-plugin"},{"cve":"CVE-2025-6013","cvss":3.1,"epss":0.005,"slug":"cve-2025-6013-hashicorp-vault-ldap-auth-method-may-not-have-correctly-enforced","title":"GO-2025-3848 - HashiCorp Vault ldap auth method may not have correctly enforced MFA in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6013-hashicorp-vault-ldap-auth-method-may-not-have-correctly-enforced"},{"cve":"CVE-2025-6011","cvss":3.1,"epss":0.0034,"slug":"cve-2025-6011-hashicorp-vault-has-an-observable-discrepancy-on-existing-and-non","title":"GO-2025-3839 - Hashicorp Vault has an Observable Discrepancy on Existing and Non-Existing Users in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-6011-hashicorp-vault-has-an-observable-discrepancy-on-existing-and-non"},{"cve":"CVE-2025-4656","cvss":3.1,"epss":0.0027,"slug":"cve-2025-4656-vault-community-edition-rekey-and-recovery-key-operations-can","title":"GO-2025-3788 - Vault Community Edition rekey and recovery key operations can cause denial of service in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-07-28T19:57:13+00:00","url":"https://junglewise.ai/threats/cve-2025-4656-vault-community-edition-rekey-and-recovery-key-operations-can"},{"cve":"CVE-2025-4166","cvss":3.1,"epss":0.0043,"slug":"cve-2025-4166-hashicorp-vault-community-vulnerable-to-generation-of-error","title":"GO-2025-3663 - Hashicorp Vault Community vulnerable to Generation of Error Message Containing Sensitive Information in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-05-06T15:37:19+00:00","url":"https://junglewise.ai/threats/cve-2025-4166-hashicorp-vault-community-vulnerable-to-generation-of-error"},{"cve":"CVE-2025-3879","cvss":3.1,"epss":0.0042,"slug":"cve-2025-3879-hashicorp-vault-community-vulnerable-to-incorrect-authorization","title":"GO-2025-3662 - Hashicorp Vault Community vulnerable to Incorrect Authorization in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2025-05-06T15:37:19+00:00","url":"https://junglewise.ai/threats/cve-2025-3879-hashicorp-vault-community-vulnerable-to-incorrect-authorization"},{"cve":"CVE-2024-8185","cvss":3.1,"epss":0.0048,"slug":"cve-2024-8185-hashicorp-vault-vulnerable-to-denial-of-service-through-memory","title":"GO-2024-3246 - Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-11-01T21:56:16+00:00","url":"https://junglewise.ai/threats/cve-2024-8185-hashicorp-vault-vulnerable-to-denial-of-service-through-memory"},{"cve":"CVE-2024-9180","cvss":3.1,"epss":0.0053,"slug":"cve-2024-9180-vault-community-edition-privilege-escalation-vulnerability","title":"GO-2024-3191 - Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-10-11T14:32:39+00:00","url":"https://junglewise.ai/threats/cve-2024-9180-vault-community-edition-privilege-escalation-vulnerability"},{"cve":"CVE-2024-7594","cvss":3.1,"epss":0.0027,"slug":"cve-2024-7594-vault-ssh-secrets-engine-configuration-did-not-restrict-valid","title":"GO-2024-3162 - Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-10-09T20:29:23+00:00","url":"https://junglewise.ai/threats/cve-2024-7594-vault-ssh-secrets-engine-configuration-did-not-restrict-valid"},{"cve":"CVE-2024-8365","cvss":3.1,"epss":0.0046,"slug":"cve-2024-8365-vault-leaks-client-token-and-token-accessor-in-audit-devices","title":"GO-2024-3113 - Vault Leaks Client Token and Token Accessor in Audit Devices in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-09-06T20:43:50+00:00","url":"https://junglewise.ai/threats/cve-2024-8365-vault-leaks-client-token-and-token-accessor-in-audit-devices"},{"cve":"CVE-2022-40186","cvss":3.1,"epss":0.01,"slug":"cve-2022-40186-hashicorp-vault-vulnerable-to-incorrect-metadata-access","title":"GO-2022-1021 - HashiCorp Vault vulnerable to incorrect metadata access in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:24+00:00","url":"https://junglewise.ai/threats/cve-2022-40186-hashicorp-vault-vulnerable-to-incorrect-metadata-access"},{"cve":"CVE-2020-16250","cvss":3.1,"epss":0.0151,"slug":"cve-2020-16250-authentication-bypass-by-spoofing-and-insufficient-verification","title":"GO-2022-0825 - Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:02+00:00","url":"https://junglewise.ai/threats/cve-2020-16250-authentication-bypass-by-spoofing-and-insufficient-verification"},{"cve":"CVE-2020-7220","cvss":3.1,"epss":0.0142,"slug":"cve-2020-7220-improper-resource-shutdown-or-release-in-hashicorp-vault","title":"GO-2022-0816 - Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:02+00:00","url":"https://junglewise.ai/threats/cve-2020-7220-improper-resource-shutdown-or-release-in-hashicorp-vault"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/hashicorp/vault (Go)","slug":"github-com-hashicorp-vault","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://www.vaultproject.io/","repo_url":"https://github.com/hashicorp/vault","description":"A tool for secrets management, encryption as a service, and privileged access management.","url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault"},"most_severe":[{"cve":"CVE-2026-3605","cvss":8.1,"epss":0.005,"slug":"cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine","title":"HashiCorp Vault policy bypass in KVv2 secrets engine","severity":"high","exploited":false,"published_at":"2026-04-17T04:16:03.263+00:00","url":"https://junglewise.ai/threats/cve-2026-3605-hashicorp-vault-policy-bypass-in-kvv2-secrets-engine"},{"cve":"CVE-2026-5807","cvss":7.5,"epss":0.0091,"slug":"cve-2026-5807-hashicorp-vault-denial-of-service-in-root-token-generation-and","title":"HashiCorp Vault denial of service in root token generation and rekeying","severity":"high","exploited":false,"published_at":"2026-04-17T05:16:19.303+00:00","url":"https://junglewise.ai/threats/cve-2026-5807-hashicorp-vault-denial-of-service-in-root-token-generation-and"},{"cve":"CVE-2026-4525","cvss":7.5,"epss":0.0059,"slug":"cve-2026-4525-hashicorp-vault-token-disclosure-in-auth-plugin-header-forwarding","title":"HashiCorp Vault token disclosure in auth plugin header forwarding","severity":"high","exploited":false,"published_at":"2026-04-17T04:16:09.997+00:00","url":"https://junglewise.ai/threats/cve-2026-4525-hashicorp-vault-token-disclosure-in-auth-plugin-header-forwarding"},{"cve":"CVE-2026-5052","cvss":5.3,"epss":0.0039,"slug":"cve-2026-5052-hashicorp-vault-ssrf-in-pki-engine-acme-validation","title":"HashiCorp Vault SSRF in PKI engine ACME validation","severity":"medium","exploited":false,"published_at":"2026-04-17T06:31:07+00:00","url":"https://junglewise.ai/threats/cve-2026-5052-hashicorp-vault-ssrf-in-pki-engine-acme-validation"},{"cve":"CVE-2020-16251","cvss":3.1,"epss":0.0283,"slug":"cve-2020-16251-hashicorp-vault-authentication-bypass","title":"GO-2024-2488 - HashiCorp Vault Authentication bypass in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-16251-hashicorp-vault-authentication-bypass"},{"cve":"CVE-2020-16250","cvss":3.1,"epss":0.0151,"slug":"cve-2020-16250-authentication-bypass-by-spoofing-and-insufficient-verification","title":"GO-2022-0825 - Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:02+00:00","url":"https://junglewise.ai/threats/cve-2020-16250-authentication-bypass-by-spoofing-and-insufficient-verification"},{"cve":"CVE-2020-7220","cvss":3.1,"epss":0.0142,"slug":"cve-2020-7220-improper-resource-shutdown-or-release-in-hashicorp-vault","title":"GO-2022-0816 - Improper Resource Shutdown or Release in HashiCorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:02+00:00","url":"https://junglewise.ai/threats/cve-2020-7220-improper-resource-shutdown-or-release-in-hashicorp-vault"},{"cve":"CVE-2021-32923","cvss":3.1,"epss":0.0138,"slug":"cve-2021-32923-invalid-session-token-expiration","title":"GO-2022-0623 - Invalid session token expiration in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2021-32923-invalid-session-token-expiration"},{"cve":"CVE-2020-35177","cvss":3.1,"epss":0.0131,"slug":"cve-2020-35177-enumeration-of-users-in-hashicorp-vault","title":"GO-2024-2508 - Enumeration of users in HashiCorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2020-35177-enumeration-of-users-in-hashicorp-vault"},{"cve":"CVE-2021-3282","cvss":3.1,"epss":0.013,"slug":"cve-2021-3282-improper-authentication-in-hashicorp-vault","title":"GO-2024-2509 - Improper Authentication in HashiCorp Vault in github.com/hashicorp/vault","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2021-3282-improper-authentication-in-hashicorp-vault"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}