Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openbao — Vulnerabilities & Security Advisories 32

Browse all 32 CVE security advisories affecting openbao. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Openbao serves as an open-source fork of HashiCorp Vault, primarily functioning as a secrets management and identity-based authorization platform for securing digital assets. Its core utility lies in centralizing access control for sensitive data, API keys, and certificates across complex infrastructure. Historically, vulnerability records indicate a prevalence of issues related to improper access control and potential privilege escalation, with some instances involving remote code execution vectors. These flaws often stem from complex configuration logic or input validation gaps within the API layer. While no catastrophic, widespread breaches have been publicly documented as direct results of these twenty CVEs, the presence of such vulnerabilities highlights the inherent risks in distributed secret management systems. The project maintains a focus on community-driven security audits to mitigate these risks, ensuring that the tool remains a viable alternative for organizations requiring transparent, auditable secrets management solutions without proprietary constraints.

Top products by openbao: openbao openbao-plugins
CVE ID Title CVSS Severity Published
CVE-2026-63132 OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack — openbao CWE-208 9.2 Critical 2026-09-23
CVE-2026-63131 OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix) — openbao CWE-863 6.0 Medium 2026-09-23
CVE-2026-77285 OpenBao Agent Writes Secrets to Stdout — openbao CWE-532 2.4 Low 2026-09-23
CVE-2026-71543 OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters — openbao CWE-863 7.5 High 2026-09-21
CVE-2026-55770 OpenBao: LDAPi ldaputil (wrong escape func) — openbao CWE-90 6.8 Medium 2026-09-15
CVE-2026-55776 OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types — openbao CWE-617 6.5 Medium 2026-09-15
CVE-2026-55774 OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} — incomplete fix of CVE-2026-45808 — openbao CWE-863 2.1 Low 2026-09-15
CVE-2026-55775 OpenBao's System Backend allows Unauthorized Management of the containing Namespace — openbao CWE-285 2.3 Low 2026-09-15
CVE-2026-45808 OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL — openbao CWE-863 7.1 High 2026-08-07
CVE-2026-46405 OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens — openbao CWE-770 5.3 Medium 2026-08-07
CVE-2026-46358 OpenBao's Inline Auth Incorrectly Redacted Headers — openbao CWE-532 5.4 Medium 2026-08-07
CVE-2026-42186 OpenBao's Namespace Deletion May Not Delete Data Properly — openbao CWE-212 - - 2026-05-14
CVE-2026-40264 OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation — openbao CWE-1259 8.1AI High AI 2026-04-21
CVE-2026-39396 OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) — openbao CWE-400 3.1 Low 2026-04-21
CVE-2026-39388 OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate — openbao CWE-295 7.5AI High AI 2026-04-21
CVE-2026-39946 OpenBao allows SQL Injection in PostgreSQL database secrets engine — openbao CWE-89 8.8 - 2026-04-21
CVE-2026-33758 OpenBao has Reflected XSS in its OIDC authentication error message — openbao CWE-20 6.1 - 2026-03-27
CVE-2026-33757 OpenBao lacks user confirmation for OIDC direct callback mode — openbao CWE-384 9.6 Critical 2026-03-27
CVE-2025-64761 OpenBao Privileged Operator Identity Group Root Escalation — openbao CWE-266 7.2AI High AI 2025-11-25
CVE-2025-59048 OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method — openbao-plugins CWE-863 8.1 High 2025-10-23
CVE-2025-62705 OpenBao and Vault Leak []byte Fields in Audit Logs — openbao CWE-532 7.5AI High AI 2025-10-22
CVE-2025-62513 OpenBao leaks HTTPRawBody in Audit Logs — openbao CWE-532 7.5AI High AI 2025-10-22
CVE-2025-59043 OpenBao vulnerable to denial of service via malicious JSON request processing — openbao CWE-400 7.5 High 2025-10-17
CVE-2025-55003 OpenBao Login MFA Bypasses Rate Limiting and TOTP Token Reuse — openbao CWE-307 5.7 Medium 2025-08-09
CVE-2025-55001 OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias — openbao CWE-156 6.5 Medium 2025-08-09
CVE-2025-55000 OpenBao TOTP Secrets Engine Enables Code Reuse — openbao CWE-156 6.5 Medium 2025-08-09
CVE-2025-54999 OpenBao: Timing Side-Channel in Userpass Auth Method — openbao CWE-203 3.7 Low 2025-08-09
CVE-2025-54998 OpenBao Userpass and LDAP User Lockout Bypass — openbao CWE-307 5.3 Medium 2025-08-09
CVE-2025-54997 OpenBao: Privileged Operator May Execute Code on the Underlying Host — openbao CWE-94 9.1 Critical 2025-08-09
CVE-2025-54996 OpenBao Root Namespace Operator May Elevate Token Privileges — openbao CWE-269 7.2 High 2025-08-09

This page lists every published CVE security advisory associated with openbao. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.