HashiCorp Vault是美国HashiCorp公司的一款私钥访问管理工具。 HashiCorp Vault 2.0.0之前版本、1.21.5之前版本、1.20.10之前版本和1.19.16之前版本存在安全漏洞,该漏洞源于Vault将令牌转发到身份验证插件后端。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Vault | 0.11.2< 2.0.0 |
affected |
| HashiCorp | Vault Enterprise | 0.11.2< 2.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Vault | 0.11.2 ~ 2.0.0 | - |
|
| HashiCorp | Vault Enterprise | 0.11.2 ~ 2.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-3605 | 8.1 HIGH | Vault KVv2 Metadata and Secret Deletion Policy Bypass Denial-of-Service |
| CVE-2026-5807 | 7.5 HIGH | Vault Vulnerable to Denial-of-Service via Unauthenticated Root Token Generation/Rekey Oper |
| CVE-2026-5052 | 5.3 MEDIUM | Vault Vulnerable to Server-Side Request Forgery in ACME Challenge Validation via Attacker- |
No comments yet