Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/hashicorp/vault
  4. ›
  5. CVE-2025-4656

CVE-2025-4656: Vault Community Edition rekey and recovery key operations can cause denial of service

June 26, 2025 (updated June 27, 2025)

Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled cancellation by a Vault operator. This vulnerability (CVE-2025-4656) has been remediated in Vault Community Edition 1.20.0 and Vault Enterprise 1.20.0, 1.19.6, 1.18.11, 1.17.17, and 1.16.22.

References

  • discuss.hashicorp.com/t/hcsec-2025-11-vault-vulnerable-to-recovery-key-cancellation-denial-of-service/75570
  • github.com/advisories/GHSA-fhc2-8qx8-6vj7
  • github.com/hashicorp/vault
  • github.com/hashicorp/vault/pull/30794
  • nvd.nist.gov/vuln/detail/CVE-2025-4656

Code Behaviors & Features

Detect and mitigate CVE-2025-4656 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.14.8 before 1.20.0

Fixed versions

  • 1.20.0

Solution

Upgrade to version 1.20.0 or above.

Impact 3.1 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-1088: Synchronous Access of Remote Resource without Timeout

Source file

go/github.com/hashicorp/vault/CVE-2025-4656.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:18:51 +0000.