Affected by GO-2025-4070
and 5 other vulnerabilities
GO-2025-4070: HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass in github.com/hashicorp/vault
GO-2025-4071: Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON in github.com/hashicorp/vault
GO-2026-5199: HashiCorp Vault May Expose Tokens to Auth Plugins Due to Incorrect Header Sanitization in github.com/hashicorp/vault
GO-2026-5247: HashiCorp Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Operations in github.com/hashicorp/vault
GO-2026-5262: HashiCorp Vault has Server-Side Request Forgery in ACME Challenge Validation via Attacker-Controlled DNS in github.com/hashicorp/vault
GO-2026-5487: HashiCorp Vault has a KVv2 Metadata and Secret Deletion Policy Bypass that leads to Denial-of-Service in github.com/hashicorp/vault
command
Version:
v1.21.0-rc1
Opens a new window with list of versions in this module.
Published: Oct 9, 2025
License:
UNKNOWN
not legal advice
Opens a new window with license information.
Imports: 4
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation not displayed due to license restrictions.
See our license policy.
Click to show internal directories.
Click to hide internal directories.