Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

openbao — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in openbao, with AI-generated Chinese analysis, references, and POCs.

This page aggregates common weakness type data for the openbao product. It covers the period from 2023 to 2024 and lists vulnerabilities affecting various versions of the software. The content focuses on known security issues that have been publicly disclosed and analyzed. Here, users can track vendor advisories related to openbao and understand the nature of specific weakness classes. The page provides a historical record of vulnerabilities, allowing researchers and developers to look up past incidents and assess the impact on their systems. By consolidating these details, the resource supports informed decision-making regarding patching and mitigation strategies. The information is presented to help security professionals identify trends and prioritize fixes based on severity and availability. All entries are sourced from official channels and verified databases to ensure accuracy. This aggregation serves as a reference point for understanding the security posture of openbao over time. It highlights areas of concern and provides context for each reported issue. Users can explore the data to gain insights into potential risks and required actions. The goal is to facilitate better protection against known threats by providing comprehensive and organized information. This approach supports proactive security management and helps maintain system integrity. The data is regularly updated to reflect the latest developments in vulnerability research.

Vendor: openbao

CVE ID Title CVSS Severity Published
CVE-2026-45808 OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL CWE-863 7.1 High 2026-08-07
CVE-2026-46405 OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens CWE-770 5.3 Medium 2026-08-07
CVE-2026-46358 OpenBao's Inline Auth Incorrectly Redacted Headers CWE-532 5.4 Medium 2026-08-07
CVE-2026-42186 OpenBao's Namespace Deletion May Not Delete Data Properly CWE-212 - - 2026-05-14
CVE-2026-40264 OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation CWE-1259 8.1AI High AI 2026-04-21
CVE-2026-39396 OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) CWE-400 3.1 Low 2026-04-21
CVE-2026-39388 OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate CWE-295 7.5AI High AI 2026-04-21
CVE-2026-39946 OpenBao allows SQL Injection in PostgreSQL database secrets engine CWE-89 8.8 - 2026-04-21
CVE-2026-33758 OpenBao has Reflected XSS in its OIDC authentication error message CWE-20 6.1 - 2026-03-27
CVE-2026-33757 OpenBao lacks user confirmation for OIDC direct callback mode CWE-384 9.6 Critical 2026-03-27
CVE-2025-64761 OpenBao Privileged Operator Identity Group Root Escalation CWE-266 7.2AI High AI 2025-11-25
CVE-2025-62705 OpenBao and Vault Leak []byte Fields in Audit Logs CWE-532 7.5AI High AI 2025-10-22
CVE-2025-62513 OpenBao leaks HTTPRawBody in Audit Logs CWE-532 7.5AI High AI 2025-10-22
CVE-2025-59043 OpenBao vulnerable to denial of service via malicious JSON request processing CWE-400 7.5 High 2025-10-17
CVE-2025-55003 OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuse CWE-307 5.7 Medium 2025-08-09
CVE-2025-55001 OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias CWE-156 6.5 Medium 2025-08-09
CVE-2025-55000 OpenBao TOTP Secrets Engine Enables Code Reuse CWE-156 6.5 Medium 2025-08-09
CVE-2025-54999 OpenBao: Timing Side-Channel in Userpass Auth Method CWE-203 3.7 Low 2025-08-09
CVE-2025-54998 OpenBao Userpass and LDAP User Lockout Bypass CWE-307 5.3 Medium 2025-08-09
CVE-2025-54997 OpenBao: Privileged Operator May Execute Code on the Underlying Host CWE-94 9.1 Critical 2025-08-09
CVE-2025-54996 OpenBao Root Namespace Operator May Elevate Token Privileges CWE-269 7.2 High 2025-08-09
CVE-2025-52894 OpenBao Vulnerable to Unauthenticated Rekey Operation Cancellation CWE-20 7.5AI High AI 2025-06-25
CVE-2025-52893 OpenBao May Leak Sensitive Information in Logs When Processing Malformed Data CWE-532 4.5 Medium 2025-06-25

All 23 known CVE vulnerabilities affecting openbao with full Chinese analysis, references, and POCs where available.