openbaoGHSA-34fc-gh42-pj53
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CriticalCVE-2026-63132 · Published Sep 22, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/openbao/openbao Go | < 0.0.0-20260713141742-763625a20721 | 0.0.0-20260713141742-763625a20721 |
| >= 0.1.0, <= 1.1.5 | No fix yet |
Details and references
### Impact When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance, including reading or modification of data. ### Patches This has been patched in OpenBao v2.6.0.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-208
- Also known as
- CVE-2026-63132
- github.com/openbao/openbao/security/advisories/GHSA-34fc-gh42-pj53
- github.com/openbao/openbao/pull/3388
- github.com/openbao/openbao/pull/3472
- github.com/openbao/openbao/commit/0f2d90c331f25d1c6cd108638da03f4c7bd949a8
- github.com/hashicorp/vault/blob/main/CHANGELOG.md#203
- github.com/openbao/openbao
- github.com/openbao/openbao/releases/tag/v2.6.0
More openbao advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | OpenBao Agent Writes Secrets to Stdout CVE-2026-77285Lowfixed in 0.0.0-20260714163218-90272575e5f5 | Low | 0.0.0-20260714163218-90272575e5f5 |
| Sep 22 | OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5 | High | 0.0.0-20260710001938-2d4ebafec5c5 |
| Sep 22 | OpenBao Skips Stricter Deny Policy for LIST operations CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e | Medium | 0.0.0-20260713133043-f58d848c139e |
| Jun 19 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types CVE-2026-55776Medium6.5fixed in 0.0.0-20260617104123-db57c62602b2 | Medium6.5 | 0.0.0-20260617104123-db57c62602b2 |
| Jun 19 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae | Low | 0.0.0-20260617103935-d3c1cc64b1ae |
| Jun 19 | OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808 CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404 | Low | 0.0.0-20260617103932-b20b999dd404 |