Skip to content
vaultGHSA-4qhc-v8r6-8vwm

HashiCorp Vault Missing Release of Memory after Effective Lifetime vulnerability

High7.5CVE-2023-5954 · Published Nov 9, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/vault
Go
< 1.13.101.13.10
>= 1.14.0, < 1.14.61.14.6
>= 1.15.0, < 1.15.21.15.2
Details and references

HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.10.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-401
Also known as
BIT-vault-2023-5954, CVE-2023-5954, GO-2023-2329

More vault advisories

All
DateAdvisory
Dec 92023Memory exhaustion in HashiCorp Vault
CVE-2023-6337High7.5fixed in 1.13.12, 1.14.8, 1.15.4
Sep 292023Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
CVE-2023-5077High7.6fixed in 1.13.0
Sep 152023HashiCorp Vault Improper Input Validation vulnerability
CVE-2023-4680Medium6.8fixed in 1.12.11, 1.13.7, 1.14.3
Jan 302024HashiCorp Vault Improper Privilege Management
CVE-2020-10661Critical9.1fixed in 1.3.4
Jan 302024HashiCorp Vault Improper Privilege Management
CVE-2020-10660Medium5.3fixed in 1.3.4
Jan 312024HashiCorp Vault Authentication bypass
CVE-2020-16251High8.2fixed in 1.2.5, 1.3.8, 1.4.4, 1.5.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.