VYPR

Openbao

by Openbao

Source repositories

CVEs (32)

  • CVE-2026-33757CriMar 27, 2026
    risk 0.55cvss 9.6epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` set to `direct`. This allows an attacker to start an authentication request and…

  • CVE-2024-2048HigMar 4, 2024
    risk 0.53cvss 8.1epss 0.00

    Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be…

  • CVE-2025-54997CriAug 9, 2025
    risk 0.52cvss 9.1epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators from executing system code or making…

  • CVE-2026-42186HigMay 14, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as…

  • CVE-2025-62513HigOct 22, 2025
    risk 0.42cvss 7.5epss 0.00

    OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC'd). This impacts those using the ACME functionality of…

  • CVE-2025-59043HigOct 17, 2025
    risk 0.42cvss 7.5epss 0.01

    OpenBao is an open source identity-based secrets management system. In OpenBao versions prior to 2.4.1, JSON objects after decoding may use significantly more memory than their serialized version. It is possible to craft a JSON payload to maximize the factor between serialized…

  • CVE-2025-52894HigJun 25, 2025
    risk 0.42cvss 7.5epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 allowed an attacker to perform unauthenticated, unaudited cancellation of root rekey and recovery rekey operations,…

  • CVE-2024-8185HigOct 31, 2024
    risk 0.42cvss 7.5epss 0.00

    Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft cluster join API endpoint . An attacker may send a large volume of requests to the…

  • CVE-2024-7594HigSep 26, 2024
    risk 0.42cvss 7.5epss 0.00

    Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets…

  • CVE-2025-64761HigNov 25, 2025
    risk 0.40cvss 7.2epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could use the identity group subsystem to add a root policy to a group identity group, escalating their or another user's permissions in the system. Specifically…

  • CVE-2025-54996HigAug 9, 2025
    risk 0.40cvss 7.2epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, accounts with access to highly-privileged identity entity systems in root namespaces were able to increase their…

  • CVE-2024-9180HigOct 10, 2024
    risk 0.40cvss 7.2epss 0.01

    A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.

  • CVE-2026-45808HigAug 7, 2026
    risk 0.39cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A tenant who intentionally leaks lease identifiers can have their lease and underlying credential revoked or renewed by a user in…

  • CVE-2025-55001MedAug 9, 2025
    risk 0.35cvss 6.5epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allowed the assignment of policies and MFA attribution based upon entity aliases, chosen by the…

  • CVE-2025-55000MedAug 9, 2025
    risk 0.35cvss 6.5epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's TOTP secrets engine could accept valid codes multiple times rather than strictly-once. This was…

  • CVE-2026-33758MedMar 27, 2026
    risk 0.33cvss 6.1epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on…

  • CVE-2025-55003MedAug 9, 2025
    risk 0.30cvss 5.7epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao's Login Multi-Factor Authentication (MFA) system allows enforcing MFA using Time-based One Time Password…

  • CVE-2026-46358MedAug 7, 2026
    risk 0.28cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires…

  • CVE-2026-46405MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, or when an `Authorization: Negotiate` header is supplied, the response is includes a `logical.Auth` object in addition to an error…

  • CVE-2025-54998MedAug 9, 2025
    risk 0.27cvss 5.3epss 0.00

    OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, attackers could bypass the automatic user lockout mechanisms in the OpenBao Userpass or LDAP auth systems.…

Page 1 of 2