OpenBao 是一款基于身份的开源密钥管理系统。在 2.5.5 版本之前,拥有对 路径写权限的已认证 OpenBao 调用者,通过将 参数设置为 ,同时 参数选择 、 或 ,可以终止服务器进程。 在 和 中的 Transit 策略创建路径在处理这种无效的“非对称派生密钥”组合时,可能触发一个错误路径,导致对同一互斥锁(mutex)执行双重解锁,从而引发 panic、HTTP 响应缺失、进程退出,最终造成拒绝服务(DoS)。 通过 JSON 或 HCL 格式的密钥创建请求均可表达该触发条件。此问题已在 2.5.5
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55770 | 6.8 MEDIUM | OpenBao: LDAPi ldaputil (wrong escape func) |
| CVE-2026-55775 | 2.3 LOW | OpenBao's System Backend allows Unauthorized Management of the containing Namespace |
| CVE-2026-55774 | 2.1 LOW | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} |
No comments yet