Technology · Go
github.com/openbao/openbao (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in github.com/openbao/openbao (Go): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46405, was published on 28 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About github.com/openbao/openbao (Go)
An open-source fork of HashiCorp Vault for managing secrets, identities, and sensitive data.
Latest github.com/openbao/openbao (Go) vulnerabilities
- CVE-2026-46405: OpenBao Kerberos auth method orphaned token accumulationmediumCVSS 5.3EPSS 0.6%
- CVE-2026-46358: OpenBao sensitive information disclosure in audit logsmediumCVSS 4EPSS 0.2%
- CVE-2026-45808: OpenBao authorization bypass in sys/revoke and sys/renew endpointshighCVSS 4EPSS 0.4%
- CVE-2026-42186: OpenBao improper data removal during namespace deletion retryhighCVSS 7.5EPSS 0.4%
- CVE-2026-40264: OpenBao's Token Store Allows Cross-Namespace Renewal, RevocationmediumCVSS 4EPSS 0.4%
- CVE-2026-39946: OpenBao's SQL Injection in PostgreSQL database secrets enginemediumCVSS 4.9EPSS 0.4%
- CVE-2026-39396: OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)lowCVSS 3.1EPSS 0.3%
- CVE-2026-39388: OpenBao's Certificate Authentication Allows Token Renewal With Different CertificatelowCVSS 3.1EPSS 0.1%
- CVE-2026-33758: OpenBao reflected XSS in OIDC authentication callbackmediumCVSS 6.1EPSS 0.4%
- CVE-2026-33757: OpenBao session fixation via OIDC direct callback modecriticalCVSS 9.6EPSS 0.6%
- CVE-2025-64761: GO-2025-4156 - OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation in github.com/openbao/openbaomediumCVSS 4EPSS 0.4%
- CVE-2025-59043: GO-2025-4039 - OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON…lowCVSS 3.1EPSS 0.7%
- CVE-2025-62705: GO-2025-4052 - OpenBao and Vault Leak []byte Fields in Audit Logs in github.com/openbao/openbaomediumCVSS 4EPSS 0.3%
- CVE-2025-62513: GO-2025-4049 - OpenBao leaks HTTPRawBody in Audit Logs in github.com/openbao/openbaomediumCVSS 4EPSS 0.3%
- CVE-2025-54997: GO-2025-3858 - Privileged OpenBao Operator May Execute Code on the Underlying Host in github.com/openbao/openbaolowCVSS 3.1EPSS 0.4%
- CVE-2025-54996: GO-2025-3857 - OpenBao Root Namespace Operator May Elevate Token Privileges in github.com/openbao/openbaolowCVSS 3.1EPSS 0.3%
- CVE-2025-55000: GO-2025-3853 - OpenBao TOTP Secrets Engine Code Reuse in github.com/openbao/openbaolowCVSS 3.1EPSS 0.2%
- CVE-2025-55003: GO-2025-3856 - OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse in github.com/openbao/openbaolowCVSS 3.1EPSS 0.2%
- CVE-2025-54999: GO-2025-3854 - OpenBao has a Timing Side-Channel in the Userpass Auth Method in github.com/openbao/openbaolowCVSS 3.1EPSS 0.2%
- CVE-2025-54998: GO-2025-3855 - OpenBao Userpass and LDAP User Lockout Bypass in github.com/openbao/openbaolowCVSS 3.1EPSS 0.2%
- CVE-2025-55001: GO-2025-3859 - OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias in github.com/openbao/openbaolowCVSS 3.1EPSS 0.2%
- CVE-2025-52894: GO-2025-3783 - OpenBao allows cancellation of root rekey and recovery rekey operations without authentication in…mediumCVSS 4EPSS 0.4%
- CVE-2024-8185: GO-2024-3246 - Hashicorp Vault vulnerable to denial of service through memory exhaustion in github.com/hashicorp/vaultlowCVSS 3.1EPSS 0.5%
- CVE-2024-9180: GO-2024-3191 - Vault Community Edition privilege escalation vulnerability in github.com/hashicorp/vaultlowCVSS 3.1EPSS 0.5%
Most severe github.com/openbao/openbao (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33757: OpenBao session fixation via OIDC direct callback modecriticalCVSS 9.6EPSS 0.6%
- CVE-2026-42186: OpenBao improper data removal during namespace deletion retryhighCVSS 7.5EPSS 0.4%
- CVE-2026-45808: OpenBao authorization bypass in sys/revoke and sys/renew endpointshighCVSS 4EPSS 0.4%
- CVE-2026-33758: OpenBao reflected XSS in OIDC authentication callbackmediumCVSS 6.1EPSS 0.4%
- CVE-2026-46405: OpenBao Kerberos auth method orphaned token accumulationmediumCVSS 5.3EPSS 0.6%
- CVE-2026-39946: OpenBao's SQL Injection in PostgreSQL database secrets enginemediumCVSS 4.9EPSS 0.4%
- CVE-2025-52894: GO-2025-3783 - OpenBao allows cancellation of root rekey and recovery rekey operations without authentication in…mediumCVSS 4EPSS 0.4%
- CVE-2026-40264: OpenBao's Token Store Allows Cross-Namespace Renewal, RevocationmediumCVSS 4EPSS 0.4%
- CVE-2025-64761: GO-2025-4156 - OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation in github.com/openbao/openbaomediumCVSS 4EPSS 0.4%
- CVE-2025-62705: GO-2025-4052 - OpenBao and Vault Leak []byte Fields in Audit Logs in github.com/openbao/openbaomediumCVSS 4EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-openbao-openbao.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/openbao/openbao (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-openbao-openbao, 26 September 2026.