📦 Openbao

by Openbao

🔍 What is Openbao?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54997

CRITICAL CVSS 9.1 Aug 9, 2025

This vulnerability allows privileged OpenBao operators to bypass security restrictions and execute arbitrary code on the underlying host by manipulating log prefixes through the audit subsystem. It af...

CVE-2025-64761

HIGH CVSS 7.2 Nov 25, 2025

OpenBao versions before 2.4.4 contain a privilege escalation vulnerability where privileged operators without policy access can add root policies to identity groups, granting root-equivalent permissio...

CVE-2025-62513

HIGH CVSS 7.5 Oct 22, 2025

OpenBao versions 2.2.0 to 2.4.1 have an audit log regression where raw HTTP bodies for certain endpoints aren't properly redacted. This leaks ACME verification challenge codes and OIDC auth/token resp...

CVE-2025-59043

HIGH CVSS 7.5 Oct 17, 2025

OpenBao versions before 2.4.1 have a memory exhaustion vulnerability where specially crafted JSON payloads can cause disproportionate memory consumption during deserialization, similar to a zip bomb. ...

CVE-2025-52894

HIGH CVSS 7.5 Jun 25, 2025

OpenBao before version 2.3.0 allows unauthenticated attackers to cancel root rekey and recovery rekey operations, causing denial of service. This affects all OpenBao deployments with default configura...

CVE-2024-8185

HIGH CVSS 7.5 Oct 31, 2024

This vulnerability allows attackers to cause denial-of-service through memory exhaustion by sending excessive requests to Vault's Raft cluster join API endpoint. It affects Vault Community and Enterpr...

CVE-2024-9180

HIGH CVSS 7.2 Oct 10, 2024

This vulnerability allows a Vault operator with write permissions to the root namespace's identity endpoint to escalate their own or another user's privileges to Vault's root policy. This affects Hash...

CVE-2025-55003

MEDIUM CVSS 5.7 Aug 9, 2025

OpenBao's MFA system in versions 2.3.1 and below has a TOTP code validation flaw where whitespace in codes bypasses rate limiting, allowing attackers to reuse valid MFA tokens. This affects organizati...

CVE-2025-55000

MEDIUM CVSS 6.5 Aug 9, 2025

OpenBao's TOTP secrets engine in versions 0.1.0 through 2.3.1 allows TOTP codes to be reused multiple times due to normalization issues in the underlying library. This affects systems using OpenBao fo...

CVE-2025-55001

MEDIUM CVSS 6.5 Aug 9, 2025

OpenBao versions 2.3.1 and below contain an LDAP authentication bypass vulnerability when using username_as_alias=true parameter. Attackers can bypass multi-factor authentication (MFA) requirements by...

CVE-2025-4166

MEDIUM CVSS 4.5 May 2, 2025

CVE-2025-4166 allows sensitive information exposure in Vault server and audit logs when users submit malformed payloads during secret creation or update operations via the KV v2 plugin REST API. This ...