CVE-2025-62513: OpenBao leaks HTTPRawBody in Audit Logs
(updated )
OpenBao’s audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC’d). This impacted the following subsystems:
- When using the ACME functionality of PKI, this would result in short-lived ACME verification challenge codes being leaked in the audit logs.
- When using the OIDC issuer functionality of the identity subsystem, auth and token response codes along with claims could be leaked in the audit logs.
Third-party plugins may be affected.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-62513 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →