Skip to content
openbaoGHSA-34fc-gh42-pj53

OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack

CriticalCVE-2026-63132 · Published Sep 22, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/openbao/openbao
Go
< 0.0.0-20260713141742-763625a207210.0.0-20260713141742-763625a20721
>= 0.1.0, <= 1.1.5No fix yet
Details and references

### Impact When running in the highly privileged recovery mode, OpenBao was vulnerable to a timing attack against the single recovery token. This allowed an attacker to extract the recovery token and use it to perform operations against the OpenBao instance, including reading or modification of data. ### Patches This has been patched in OpenBao v2.6.0.

CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-208
Also known as
CVE-2026-63132

More openbao advisories

All
DateAdvisory
Sep 22OpenBao Agent Writes Secrets to Stdout
CVE-2026-77285Lowfixed in 0.0.0-20260714163218-90272575e5f5
Sep 22OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5
Sep 22OpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e
Jun 19OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types
CVE-2026-55776Medium6.5fixed in 0.0.0-20260617104123-db57c62602b2
Jun 19OpenBao's System Backend allows Unauthorized Management of the containing Namespace
CVE-2026-55775Lowfixed in 0.0.0-20260617103935-d3c1cc64b1ae
Jun 19OpenBao: Cross-namespace lease revocation/renewal via canonical sys/leases/{revoke,renew} , incomplete fix of CVE-2026-45808
CVE-2026-55774Lowfixed in 0.0.0-20260617103932-b20b999dd404

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.